UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

On Classified Systems, Logical Partition must be restricted with read/write access to only its own IOCDS.


Overview

Finding ID Version Rule ID IA Controls Severity
V-256863 HLP0020 SV-256863r958472_rule Medium
Description
Unrestricted control over the IOCDS files could result in unauthorized updates and impact the configuration of the environment by allowing unauthorized access to a restricted resource. This could severely damage the integrity of the environment and the system resources.
STIG Date
IBM Hardware Management Console (HMC) Security Technical Implementation Guide 2024-06-24

Details

Check Text ( C-60538r890933_chk )
Using the Hardware Management Console, verify that a logical partition cannot read or write to any IOCDS. Use the Security Definitions Page panel to do this by checking to see if the Input/Output (I/O) Configuration Control option has been turned on.

NOTE: The default is applicable to only classified systems.

Confirm whether or not the I/O Configuration Control option is checked.

If the Logical Partition is not restricted with read/write access to only its own IOCDS, this is a FINDING.
Fix Text (F-60481r890934_fix)
Review the Security Definition parameters specified under Processor Resource/Systems Manager (PR/SM).
Verify and implement the correct settings.