Skip to content

z/OS Front End Processor for RACF Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-OS-000480

    Group
  • SRG-OS-000480

    Group
  • A documented procedure is not available instructing how to load and dump the FEP NCP (Network Control Program).

    If components of the FEPs are not properly protected they can be stolen, damaged, or disturbed. Without adequate physical security, unauthorized users can access the control panel, the operator co...
    Rule Medium Severity
  • SRG-OS-000480

    Group
  • SRG-OS-000259

    Group
  • NCP (Net Work Control Program) Data set access authorization does not restricts UPDATE and/or ALLOCATE access to appropriate personnel.

    If components of the FEPs are not properly protected they can be stolen, damaged, or disturbed. Without adequate physical security, unauthorized users can access the control panel, the operator co...
    Rule Medium Severity
  • SRG-OS-000080

    Group
  • A password control is not in place to restrict access to the service subsystem via the operator consoles (local and/or remote) and a key-lock switch is not used to protect the modem supporting the remote console of the service subsystem.

    If components of the FEPs are not properly protected they can be stolen, damaged, or disturbed. Without adequate physical security, unauthorized users can access the control panel, the operator co...
    Rule Medium Severity
  • All hardware components of the FEPs are not placed in secure locations where they cannot be stolen, damaged, or disturbed

    If components of the FEPs are not properly protected they can be stolen, damaged, or disturbed. Without adequate physical security, unauthorized users can access the control panel, the operator co...
    Rule Medium Severity
  • An active log is not available to keep track of all hardware upgrades and software changes made to the FEP (Front End Processor).

    If components of the FEPs are not properly protected they can be stolen, damaged, or disturbed. Without adequate physical security, unauthorized users can access the control panel, the operator co...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules