UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

Classified Logical Partition (LPAR) channel paths must be restricted.


Overview

Finding ID Version Rule ID IA Controls Severity
V-256865 HLP0040 SV-256865r958472_rule High
Description
Restricted LPAR channel paths are necessary to ensure data integrity. Unrestricted LPAR channel path access could result in a compromise of data integrity. When a classified LPAR exists on a mainframe which requires total isolation, all paths to that LPAR must be restricted.
STIG Date
IBM Hardware Management Console (HMC) Security Technical Implementation Guide 2024-06-24

Details

Check Text ( C-60540r890939_chk )
Have the System Administrator or Systems Programmer on classified systems use the Hardware Management Console to verify that the LPAR channel paths are reserved from the rest of the LPARs.

Use the Security Definitions Panel to verify this. The Logical Partition Isolation option must be turned on.

If the Classified LPAR channel paths are not restricted then this is a FINDING.
Fix Text (F-60483r890940_fix)
Have the System Administrator or Systems Programmer for classified systems use the Hardware Management Console to verify that the LPAR channel paths are reserved from the rest of the LPARs. Use the Security Definitions Panel to verify this. The Logical Partition Isolation option must be turned on for classified systems.