An error occurred:
Close sidebar
Xylok
Home Menu
info@xylok.io
© 2026
Xylok, LLC
Version: releases-v2026.03.1 - rmfrev5
Xylok
Home Menu
info@xylok.io
© 2026
Xylok, LLC
Version: releases-v2026.03.1 - rmfrev5
Open sidebar
Navigate
Top
Search
Checks (
224
)
Print
Changes
Pages (
6/15
)
IBM z/OS RACF STIG
IBM z/OS RACF Security Technical Implementation Guide
v9 r7 (Released Jan. 5, 2026)
v9 r6 (Released Oct. 1, 2025)
v9 r5 (Released July 2, 2025)
v9 r4 (Released April 2, 2025)
v9 r3 (Released Jan. 30, 2025)
v9 r2 (Released Oct. 24, 2024)
v9 r1 (Released July 24, 2024)
v8 r14 (Released April 24, 2024)
v8 r13 (Released Jan. 24, 2024)
v8 r12 (Released July 26, 2023)
v8 r11 (Released April 27, 2023)
v8 r10 (Released Jan. 26, 2023)
v8 r9 (Released Nov. 23, 2022)
v8 r8 (Released Oct. 26, 2022)
v8 r7 (Released April 27, 2022)
v8 r6 (Released Jan. 27, 2022)
v8 r5 (Released Oct. 27, 2021)
v8 r4 (Released July 23, 2021)
v8 r3 (Released April 23, 2021)
v8 r2 (Released Jan. 22, 2021)
v8 r1 (Released Oct. 23, 2020)
v7 r3 (Released July 24, 2020)
v7 r2 (Released April 24, 2020)
v7 r1 (Released Nov. 18, 2019)
v7 r0.1 (Released April 5, 2019)
ID
Vuln ID
Title
Cat
Status
RACF-ES-000760
V-223723
The IBM RACF INACTIVE SETROPTS value must be set to 35 days.
Cat II
RACF-ES-000770
V-223724
IBM RACF PASSWORD(RULEn) SETROPTS value(s) must be properly set.
Cat II
RACF-ES-000780
V-223725
IBM RACF exit ICHPWX01 must be installed and properly configured.
Cat II
RACF-ES-000785
V-230210
IBM RACF exit ICHPWX11 for password phrases must be installed and properly configured.
Cat II
RACF-ES-000790
V-223726
The IBM RACF SETROPTS PASSWORD(MINCHANGE) value must be set to 1.
Cat II
RACF-ES-000800
V-223727
IBM RACF SETROPTS PASSWORD(INTERVAL) must be set to 60 days.
Cat II
RACF-ES-000810
V-223728
The IBM RACF PASSWORD(HISTORY) SETROPTS value must be set to five or more.
Cat II
RACF-ES-000820
V-223729
NIST FIPS-validated cryptography must be used to protect passwords in the security database.
Cat I
RACF-ES-000840
V-223731
The IBM RACF ERASE ALL SETROPTS value must be set to ERASE(ALL) on all systems.
Cat II
RACF-ES-000850
V-223732
IBM RACF DASD Management USERIDs must be properly controlled.
Cat II
RACF-ES-000860
V-257135
IBM Passtickets must be configured to be KeyEncrypted.
Cat II
RACF-FT-000010
V-223733
IBM z/OS SMF recording options for the FTP Server must be configured to write SMF records for all eligible events.
Cat II
RACF-FT-000020
V-223734
IBM RACF permission bits and user audit bits for HFS objects that are part of the FTP server component must be properly configured.
Cat II
RACF-FT-000030
V-223735
IBM z/OS data sets for the FTP server must be properly protected.
Cat II
RACF-FT-000040
V-223736
IBM z/OS FTP.DATA configuration statements must indicate a BANNER statement with the proper content.
Cat II
Prev
1...
2
3
4
5
6
7
8
9
10
...15
Next
Print
Display this benchmark in a printer-friendly format for off-line reference. This display does not include any commands.
Version Changes
If there are multiple versions of this benchmark, Xylok can display the differences between any changes in the checks.