The IBM z/OS Policy Agent must contain a policy that manages excess capacity, bandwidth, or other redundancy to limit the effects of information flooding types of denial-of-service (DoS) attacks.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-223793RACF-OS-000370SV-223793r958528_ruleCCI-001095medium
Description
DoS is a condition when a resource is not available for legitimate users. When this occurs, the organization either cannot accomplish its mission or must operate at degraded capacity.
STIGDate
IBM z/OS RACF Security Technical Implementation Guide2025-06-24

Related Frameworks

2 paths across 2 frameworks
NIST 800-531 mapping
  • DISA · 9 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI1 mapping
CCI-001095
1.00
  • DISA · 9 · disa_xccdf · related

Details

Check Text (C-223793r958528_chk)

Examine the Policy Agent policy statements. If it can be determined that there are policy statements that manages excess capacity, this is not a finding.

Fix Text (F-25454r515068_fix)

Develop Policy application and Policy agent to manage excess capacity.