z/OS SRRAUDIT for RACF Security Technical Implementation Guide

V7 · Released 2025-02-24

You are viewing V7. This is not the latest release. View latest release (V7R2) → · Version history

Overview

VersionDateFinding Count (2)
V72025-02-24CAT I (High): 0CAT II (Medium): 2CAT III (Low): 0
STIG Description
This Security Technical Implementation Guide is published as a tool to improve the security of Department of Defense (DOD) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via email to the following address: disa.stig_spt@mail.mil.

Findings — All

Finding IDSeverityTitleDescription
V-224535
LOWMEDIUMHIGH
SRRAUDIT installation data sets must be properly protected.SRRAUDIT installation data sets have the ability to use privileged functions and/or have access to sensitive data. Failure to properly restrict access...
V-224536
LOWMEDIUMHIGH
SRRAUDIT User data sets are not properly protected.SRRAUDIT User data sets provide the capability to use privileged functions and/or have access to sensitive data. Failure to properly restrict access t...