Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-223799 | RACF-OS-000450 | SV-223799r604139_rule | Medium |
Description |
---|
IBM z/OS system administrator must develop a procedure to remove or disable emergency accounts after the crisis is resolved or 72 hours. |
STIG | Date |
---|---|
IBM z/OS RACF Security Technical Implementation Guide | 2023-06-13 |
Check Text ( C-25472r515085_chk ) |
---|
Ask the system administrator for the procedure to automatically remove or disable emergency accounts after the crisis is resolved or 72 hours. If there is no procedure, this is a finding. |
Fix Text (F-25460r515086_fix) |
---|
Develop a procedure to remove or disable emergency user accounts after the crisis is resolved or 72 hours. |