STIGQter STIGQter: STIG Summary: Mainframe Product Security Requirements Guide Version: 1 Release: 4 Benchmark Date: 24 Jan 2020:

The Mainframe Product must allow only the information system security manager (ISSM) or individuals or roles appointed by the ISSM to select which auditable events are to be audited.

DISA Rule

SV-82679r2_rule

Vulnerability Number

V-68189

Group Title

SRG-APP-000090-MFP-000115

Rule Version

SRG-APP-000090-MFP-000115

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Mainframe Product to restrict selection of auditable events to security administrators (or individuals or roles appointed by the ISSM).

Check Contents

Examine the configuration settings.

Verify the capability to select auditable events is restricted to security administrators (or individuals or roles appointed by the ISSM). If it is not, this is a finding.

Vulnerability Number

V-68189

Documentable

False

Rule Version

SRG-APP-000090-MFP-000115

Severity Override Guidance

Examine the configuration settings.

Verify the capability to select auditable events is restricted to security administrators (or individuals or roles appointed by the ISSM). If it is not, this is a finding.

Check Content Reference

M

Target Key

3061

Comments