STIGQter STIGQter: STIG Summary: IBM z/OS RACF Security Technical Implementation Guide Version: 8 Release: 3 Benchmark Date: 23 Apr 2021:

IBM RACF SETROPTS RVARYPW values must be properly set.

DISA Rule

SV-223702r604139_rule

Vulnerability Number

V-223702

Group Title

SRG-OS-000364-GPOS-00151

Rule Version

RACF-ES-000550

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure RACF ensure that the RVARYPW passwords are specified and conform to password requirements documented in RACF0460. The ISSO will evaluate the impact associated with implementation of the control option and develop a plan of action to implement the control option as required.

A sample command for setting both the SWITCH and STATUS passwords are shown here:

SETR RVARYPW(SWITCH(Wxy$8Pqu) STATUS(pbZ0@wL2))

Check Contents

From the ISPF Command Shell enter:

SETROPTS LIST

If the "INSTALLATION DEFINED RVARY PASSWORD IS IN EFFECT" message for both the SWITCH and STATUS functions, this is not a finding.

Vulnerability Number

V-223702

Documentable

False

Rule Version

RACF-ES-000550

Severity Override Guidance

From the ISPF Command Shell enter:

SETROPTS LIST

If the "INSTALLATION DEFINED RVARY PASSWORD IS IN EFFECT" message for both the SWITCH and STATUS functions, this is not a finding.

Check Content Reference

M

Target Key

4101

Comments