STIGQter STIGQter: STIG Summary: Mainframe Product Security Requirements Guide Version: 1 Release: 4 Benchmark Date: 24 Jan 2020:

The Mainframe Product must obscure feedback of authentication information during the authentication process to protect the information from possible exploitation/use by unauthorized individuals.

DISA Rule

SV-82895r1_rule

Vulnerability Number

V-68405

Group Title

SRG-APP-000178-MFP-000246

Rule Version

SRG-APP-000178-MFP-000246

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Mainframe Product account management settings to obscure feedback of authentication information during the authentication process.

Check Contents

If the Mainframe Product has no function or capability for user logon, this is not applicable.

If the Mainframe Product employs an external security manager for all account management functions, this is not applicable.

Examine Mainframe Product installation settings; examine user account configurations.

If the Mainframe Product is not configured to obscure feedback of authentication information during the authentication process, this is a finding.

Vulnerability Number

V-68405

Documentable

False

Rule Version

SRG-APP-000178-MFP-000246

Severity Override Guidance

If the Mainframe Product has no function or capability for user logon, this is not applicable.

If the Mainframe Product employs an external security manager for all account management functions, this is not applicable.

Examine Mainframe Product installation settings; examine user account configurations.

If the Mainframe Product is not configured to obscure feedback of authentication information during the authentication process, this is a finding.

Check Content Reference

M

Target Key

3061

Comments