The IBM z/OS system administrator (SA) must develop a process to notify appropriate personnel when accounts are modified.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-223763RACF-OS-000070SV-223763r998360_ruleCCI-000015medium
Description
Audit tools include, but are not limited to, vendor-provided and open source audit tools needed to successfully view and manipulate audit information system activity and records. Audit tools include custom queries and report generators.
STIGDate
IBM z/OS RACF Security Technical Implementation Guide2025-06-24

Related Frameworks

2 paths across 2 frameworks
NIST 800-531 mapping
  • DISA · 9 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI1 mapping
CCI-000015
1.00
  • DISA · 9 · disa_xccdf · related

Details

Check Text (C-223763r998360_chk)

Ask the SA for the documented process to notify appropriate personnel when accounts are modified. If there is no documented process, this is a finding.

Fix Text (F-25424r514978_fix)

Develop a documented develop a process to notify appropriate personnel when accounts are modified.