SV-93643r1_rule
V-78937
SRG-OS-000425-GPOS-00189
IBMZ-VM-001040
CAT II
10
Configure the “SECUREDATA” statement in the FTP server configuration file to specify “REQUIRED”.
Note: Care should be taken before implementing this requirement in a production environment. Develop a documented plan of action that has a definite completion date. File the plan with the ISSM.
Examine the FTP Server configuration file.
If there is no “SECUREDATA” statement, this is a finding.
If the “SECUREDATA” statement specifies “REQUIRED”, this is not a finding.
Note: If there is no "SECUREDATA" or the "SECUREDATA" specifies "ALLOWED" but there is a documented implementation plan with a definite completion date for setting "SECUREDATA" to "REQUIRED" on file with the ISSM, this can be downgraded to a CAT III.
V-78937
False
IBMZ-VM-001040
Examine the FTP Server configuration file.
If there is no “SECUREDATA” statement, this is a finding.
If the “SECUREDATA” statement specifies “REQUIRED”, this is not a finding.
Note: If there is no "SECUREDATA" or the "SECUREDATA" specifies "ALLOWED" but there is a documented implementation plan with a definite completion date for setting "SECUREDATA" to "REQUIRED" on file with the ISSM, this can be downgraded to a CAT III.
M
3211