Check: TSS0-OS-000310
IBM z/OS TSS STIG:
TSS0-OS-000310
(in versions v8 r3 through v7 r1)
Title
The IBM z/OS systems requiring data at rest protection must properly employ IBM DS8880 for full disk encryption for classified systems. (Cat II impact)
Discussion
Use of weak or untested encryption algorithms undermines the purposes of utilizing encryption to protect data. The operating system must implement cryptographic modules adhering to the higher standards approved by the federal government since this provides assurance they have been tested and validated.
Check Content
Determine if IBM's DS880 Disks are in use. If IBM DS880 Disks are not in use for systems that require data at rest, this is a finding.
Fix Text
Employ IBM's DS8880 hardware to ensure full disk encryption.
Additional Identifiers
Rule ID: SV-224027r561402_rule
Vulnerability ID: V-224027
Group Title: SRG-OS-000396-GPOS-00176
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002450 |
Implement organization-defined types of cryptography for each specified cryptography use. |
Controls
Number | Title |
---|---|
SC-13 |
Cryptographic Protection |