STIGQter STIGQter: STIG Summary: IBM z/OS RACF Security Technical Implementation Guide Version: 8 Release: 3 Benchmark Date: 23 Apr 2021:

IBM RACF SETROPTS PASSWORD(INTERVAL) must be set to 60 days.

DISA Rule

SV-223727r604139_rule

Vulnerability Number

V-223727

Group Title

SRG-OS-000076-GPOS-00044

Rule Version

RACF-ES-000800

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure PASSWORD(INTERVAL) SETROPTS value is set to "060" days. This specifies the maximum number of days that each user’s password is valid.

Evaluate the impact associated with implementation of the control option. Develop a plan of action to implement the control option as specified in the example below:

The RACF Command SETR LIST will show the status of RACF Controls including PASSWORD INTERVAL.

Setting the password interval to 60 days is activated with the command SETR PASSWORD(INTERVAL(60)).

Check Contents

From the ISPF Command Shell enter:
SETRopts List

If the PASSWORD(INTERVAL) value is set properly then the message PASSWORD CHANGE INTERVAL IS 060 DAYS, this is not a finding.

Vulnerability Number

V-223727

Documentable

False

Rule Version

RACF-ES-000800

Severity Override Guidance

From the ISPF Command Shell enter:
SETRopts List

If the PASSWORD(INTERVAL) value is set properly then the message PASSWORD CHANGE INTERVAL IS 060 DAYS, this is not a finding.

Check Content Reference

M

Target Key

4101

Comments