UCF STIG Viewer Logo

The Mainframe Product must prompt the user for action prior to executing mobile code.


Overview

Finding ID Version Rule ID IA Controls Severity
V-205599 SRG-APP-000488-MFP-000282 SV-205599r851364_rule Medium
Description
Mobile code can cause damage to the system. It can execute without explicit action from, or notification to, a user. Actions enforced before executing mobile code include, for example, prompting users prior to opening email attachments and disabling automatic execution. This requirement applies to mobile code-enabled software, which is capable of executing one or more types of mobile code.
STIG Date
Mainframe Product Security Requirements Guide 2022-09-22

Details

Check Text ( C-5865r300024_chk )
If the Mainframe Product has no function or capability for mobile code use, this is not applicable.

Examine installation and configuration settings.

If the Mainframe Product is not configured to prompt user for action before executing mobile code, this is a finding.
Fix Text (F-5865r300025_fix)
Configure the Mainframe Product to prompt the user for action before executing mobile code.