The IBM z/OS systems requiring data at rest protection must properly employ IBM DS8880 for full disk encryption.
DISA Rule
SV-224028r561402_rule
Vulnerability Number
V-224028
Group Title
SRG-OS-000404-GPOS-00183
Rule Version
TSS0-OS-000320
Severity
CAT II
CCI(s)
- CCI-002475 - The information system implements cryptographic mechanisms to prevent unauthorized modification of organization-defined information at rest on organization-defined information system components.
- CCI-002476 - The information system implements cryptographic mechanisms to prevent unauthorized disclosure of organization-defined information at rest on organization-defined information system components.
Weight
10
Fix Recommendation
Employ IBM's DS8880 hardware to ensure full disk encryption.
Check Contents
Determine if IBM's DS880 Disks are in use.
If IBMs DS880 Disks are not in use for systems that require "data at rest", this is a finding.
Vulnerability Number
V-224028
Documentable
False
Rule Version
TSS0-OS-000320
Severity Override Guidance
Determine if IBM's DS880 Disks are in use.
If IBMs DS880 Disks are not in use for systems that require "data at rest", this is a finding.
Check Content Reference
M
Target Key
4102
Comments