Check: ACF2-OS-000340
IBM z/OS ACF2 STIG:
ACF2-OS-000340
(in versions v8 r3 through v7 r1)
Title
The IBM z/OS systems requiring data at rest protection must properly employ IBM DS8880 for full disk encryption. (Cat II impact)
Discussion
Information at rest refers to the state of information when it is located on a secondary storage device (e.g., disk drive and tape drive, when used for backups) within an operating system. This requirement addresses protection of user-generated data, as well as operating system-specific configuration data. Organizations may choose to employ different mechanisms to achieve confidentiality and integrity protections, as appropriate, in accordance with the security category and/or classification of the information. Satisfies: SRG-OS-000185-GPOS-00079, SRG-OS-000405-GPOS-00184, SRG-OS-000404-GPOS-00183, SRG-OS-000396-GPOS-00176
Check Content
Determine if IBM's DS880 Disks are in use. If they are not in use for systems that require data at rest, this is a finding.
Fix Text
Employ IBM's DS8880 hardware to ensure full disk encryption.
Additional Identifiers
Rule ID: SV-223569r533198_rule
Vulnerability ID: V-223569
Group Title: SRG-OS-000185-GPOS-00079
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001199 |
Protects the confidentiality and/or integrity of organization-defined information at rest. |
CCI-002450 |
Implement organization-defined types of cryptography for each specified cryptography use. |
CCI-002475 |
Implement cryptographic mechanisms to prevent unauthorized modification of organization-defined information at rest on organization-defined system components. |
CCI-002476 |
Implement cryptographic mechanisms to prevent unauthorized disclosure of organization-defined information at rest on organization-defined system components. |