Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-98305 | RACF-OS-000450 | SV-107409r1_rule | Medium |
Description |
---|
IBM z/OS system administrator must develop a procedure to remove or disable emergency accounts after the crisis is resolved or 72 hours. |
STIG | Date |
---|---|
IBM z/OS RACF Security Technical Implementation Guide | 2020-06-29 |
Check Text ( C-97141r1_chk ) |
---|
Ask the system administrator for the procedure to automatically remove or disable emergency accounts after the crisis is resolved or 72 hours. If there is no procedure, this is a finding. |
Fix Text (F-103981r1_fix) |
---|
Develop a procedure to remove or disable emergency user accounts after the crisis is resolved or 72 hours. |