Skip to content

Mainframe Product Security Requirements Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-APP-000473

    Group
  • SRG-APP-000474

    Group
  • SRG-APP-000475

    Group
  • SRG-APP-000477

    Group
  • SRG-APP-000480

    Group
  • SRG-APP-000484

    Group
  • SRG-APP-000485

    Group
  • SRG-APP-000488

    Group
  • SRG-APP-000492

    Group
  • The Mainframe Product must generate audit records when successful/unsuccessful attempts to access security objects occur.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-APP-000493

    Group
  • SRG-APP-000494

    Group
  • The Mainframe Product must generate audit records when successful/unsuccessful attempts to access categories of information (e.g., classification levels) occur.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-APP-000495

    Group
  • SRG-APP-000496

    Group
  • The Mainframe Product must generate audit records when successful/unsuccessful attempts to modify security objects occur.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-APP-000497

    Group
  • SRG-APP-000498

    Group
  • The Mainframe Product must generate audit records when successful/unsuccessful attempts to modify categories of information (e.g., classification levels) occur.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-APP-000499

    Group
  • SRG-APP-000500

    Group
  • The Mainframe Product must generate audit records when successful/unsuccessful attempts to delete security levels occur.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-APP-000501

    Group
  • The Mainframe Product must generate audit records when successful/unsuccessful attempts to delete security objects occur.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-APP-000502

    Group
  • SRG-APP-000503

    Group
  • The Mainframe Product must generate audit records when successful/unsuccessful logon attempts occur.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-APP-000504

    Group
  • The Mainframe Product must generate audit records for privileged activities or other system-level access.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-APP-000505

    Group
  • The Mainframe Product must generate audit records showing starting and ending time for user access to the system.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-APP-000506

    Group
  • The Mainframe Product must generate audit records when concurrent logons from different workstations occur.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-APP-000507

    Group
  • The Mainframe Product must generate audit records when successful/unsuccessful accesses to objects occur.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-APP-000508

    Group
  • SRG-APP-000509

    Group
  • The Mainframe Product must generate audit records for all account creations, modifications, disabling, and termination events.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-APP-000510

    Group
  • The Mainframe Product must generate audit records for all kernel module load, unload, and restart events, and for all program initiations.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-APP-000514

    Group
  • SRG-APP-000514

    Group
  • The Mainframe Product must implement NIST FIPS-validated cryptography to generate and validate cryptographic hashes in accordance with applicable federal laws, Executive orders, directives, policies, regulations, and standards.

    Use of weak or untested encryption algorithms undermines the purposes of using encryption to protect data. The application must implement cryptographic modules adhering to the higher standards appr...
    Rule Medium Severity
  • SRG-APP-000514

    Group
  • SRG-APP-000516

    Group
  • SRG-APP-000516

    Group
  • The Mainframe Product must provide the capability for authorized users to select a user session to capture/record or view/hear.

    Without the capability to select a user session to capture/record or view/hear, investigations into suspicious or harmful events would be hampered by the volume of information captured. The volume ...
    Rule Medium Severity
  • SRG-APP-000516

    Group
  • The Mainframe Product must provide the capability for authorized users to remotely view/hear, in real time, all content related to an established user session from a component separate from the Mainframe Product being monitored.

    Without the capability to remotely view/hear all content related to a user session, investigations into suspicious user activity would be hampered. Real-time monitoring allows authorized personnel ...
    Rule Medium Severity
  • SRG-APP-000416

    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules