UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

ACF2 PSWD GSO record value must be set to prohibit password reuse for a minimum of five generations or more.


Overview

Finding ID Version Rule ID IA Controls Severity
V-223508 ACF2-ES-000910 SV-223508r695441_rule Medium
Description
Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. If the information system or application allows the user to consecutively reuse their password when that password has exceeded its defined lifetime, the end result is a password that is not changed as per policy requirements.
STIG Date
IBM z/OS ACF2 Security Technical Implementation Guide 2023-12-18

Details

Check Text ( C-25181r695440_chk )
From an ACF command screen enter:
SET CONTROL(GSO)
LIST PSWD

If "PSWDXHIST" is not specified, this is a finding.

If "PSWDXHIST#" is set to "5" or greater, this is not a finding
Fix Text (F-25169r500658_fix)
Configure Password option "PSWXHST" is coded and "PSWXHST#" is "5" or greater.