Mainframe Product Security Requirements Guide
Rules, Groups, and Values defined within the XCCDF Benchmark
-
The Mainframe Product must update malicious code protection mechanisms whenever new releases are available in accordance with organizational configuration management policy.
Malicious software detection applications need to be constantly updated in order to identify new threats as they are discovered. All malicious software detection software must come with an update...Rule Medium Severity -
SRG-APP-000275
Group -
SRG-APP-000276
Group -
The Mainframe Product must update malicious code protection mechanisms whenever new releases are available in accordance with organizational configuration management procedures.
Malicious code includes viruses, worms, Trojan horses, and spyware. Malicious code specific to mainframes may be any code that corrupts system files. The code provides the ability for a malicious u...Rule Medium Severity -
SRG-APP-000277
Group -
The Mainframe Product must configure malicious code protection mechanisms to perform periodic scans of the information system every seven days.
Malicious code protection mechanisms include, but are not limited to, anti-virus and malware detection software. Malicious code protection mechanisms specific to Mainframe Products are designed to ...Rule Medium Severity -
SRG-APP-000290
Group -
The Mainframe Product must use cryptographic mechanisms to protect the integrity of audit tools.
Protecting the integrity of the tools used for auditing purposes is a critical step to ensuring the integrity of audit data. Audit data includes all information (e.g., audit records, audit settings...Rule Medium Severity -
SRG-APP-000291
Group -
SRG-APP-000292
Group -
SRG-APP-000293
Group -
The Mainframe Product must notify system programmers and security administrators for account disabling actions.
When application accounts are disabled, user accessibility is affected. Accounts are utilized for identifying individual users or for identifying the application processes themselves. Sending notif...Rule Medium Severity -
SRG-APP-000294
Group -
SRG-APP-000295
Group -
SRG-APP-000296
Group -
Mainframe Products requiring user access authentication must provide a logoff capability for a user-initiated communication session.
If a user cannot explicitly end an application session, the session may remain open and be exploited by an attacker; this is referred to as a zombie session. Information resources to which users g...Rule Medium Severity -
SRG-APP-000297
Group -
SRG-APP-000311
Group -
SRG-APP-000313
Group -
SRG-APP-000317
Group
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.