STIGQter STIGQter: STIG Summary: IBM z/OS RACF Security Technical Implementation Guide Version: 8 Release: 3 Benchmark Date: 23 Apr 2021:

The IBM z/OS System Administrator (SA) must develop a process to disable emergency accounts after the crisis is resolved or 72 hours.

DISA Rule

SV-223761r604139_rule

Vulnerability Number

V-223761

Group Title

SRG-OS-000123-GPOS-00064

Rule Version

RACF-OS-000050

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Develop a process to disable emergency accounts after the crisis is resolved or 72 hours.

Check Contents

Ask the system administrator for the documented process to disable emergency accounts.

If there is no documented process, this is a finding.

Examine the process, if it does not include procedures to disable emergency accounts after the crisis is resolved or 72 hours, this is a finding.

Vulnerability Number

V-223761

Documentable

False

Rule Version

RACF-OS-000050

Severity Override Guidance

Ask the system administrator for the documented process to disable emergency accounts.

If there is no documented process, this is a finding.

Examine the process, if it does not include procedures to disable emergency accounts after the crisis is resolved or 72 hours, this is a finding.

Check Content Reference

M

Target Key

4101

Comments