Version | Date | Finding Count (2) | ||
---|---|---|---|---|
6 | 2022-10-06 | CAT I (High): 0 | CAT II (Med): 2 | CAT III (Low): 0 |
STIG Description |
---|
This Security Technical Implementation Guide is published as a tool to improve the security of Department of Defense (DoD) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via email to the following address: disa.stig_spt@mail.mil. |
Finding ID | Severity | Title | Description |
---|---|---|---|
V-224296 | Medium | IBM CSSMTP Started Task name is not properly identified and/or defined to the system ACP. | IBM CSSMTP requires a started task that will be restricted to certain resources, datasets and other system functions. By defining the started task as a userid to the system ACP, It allows the ACP... |
V-224295 | Medium | IBM Communications Server Simple Mail Transfer Protocol (CSSMTP) STC data sets must be properly protected. | IBM Communications Server Simple Mail Transfer Protocol (CSSMTP) STC data sets have the ability to use privileged functions and/or have access to sensitive data. Failure to properly restrict... |