SV-82729r1_rule
V-68239
SRG-APP-000355-MFP-000139
SRG-APP-000355-MFP-000139
CAT II
10
Configure the Mainframe Product to permit authorized users to remotely view/hear, in real time, all content related to an established user session from a component separate from the Mainframe Product being monitored.
If an ESM is in use, configure rules to restrict the ability to remotely view/hear, in real time, all content related to an established user session from a component separate from the Mainframe Product being monitored to system programmers and security administrators.
If the Mainframe Product has no function or capability for session operations, this is not applicable.
Examine installation and configuration settings.
If the Mainframe Product does not have the capability to remotely view/hear, in real time, all content related to an established user session from a component separate from the Mainframe Product being monitored, this a finding.
If the Mainframe Product does not restrict this capability to system programmers and security administrators, this is a finding.
If an external security manager (ESM) is in use, verify that the ESM restricts the capability to remotely view/hear, in real time, all content related to an established user session from a component separate from the Mainframe Product being monitored to system programmers or security administrators.
If it does not, this is a finding.
V-68239
False
SRG-APP-000355-MFP-000139
If the Mainframe Product has no function or capability for session operations, this is not applicable.
Examine installation and configuration settings.
If the Mainframe Product does not have the capability to remotely view/hear, in real time, all content related to an established user session from a component separate from the Mainframe Product being monitored, this a finding.
If the Mainframe Product does not restrict this capability to system programmers and security administrators, this is a finding.
If an external security manager (ESM) is in use, verify that the ESM restricts the capability to remotely view/hear, in real time, all content related to an established user session from a component separate from the Mainframe Product being monitored to system programmers or security administrators.
If it does not, this is a finding.
M
3061