CA IDMS Security Technical Implementation Guide
Rules, Groups, and Values defined within the XCCDF Benchmark
-
SRG-APP-000133-DB-000362
<GroupDescription></GroupDescription>Group -
All installation-delivered IDMS DEVELOPER-level tasks must be properly secured.
<VulnDiscussion>Developer-level tasks that are not secured may allow anyone who signs on to IDMS to use them to access and manipulate various...Rule Medium Severity -
SRG-APP-000033-DB-000084
<GroupDescription></GroupDescription>Group -
All installation-delivered IDMS DBADMIN-level tasks must be properly secured.
<VulnDiscussion>DBA-level tasks that are not secured may allow anyone who signs on to IDMS to use them to access and manipulate various resou...Rule Medium Severity -
SRG-APP-000033-DB-000084
<GroupDescription></GroupDescription>Group -
All installation-delivered IDMS DC-Administrator-level programs must be properly secured.
<VulnDiscussion>DC Administrator-level programs that are not secured may allow unauthorized users to use them to access and manipulate variou...Rule Medium Severity -
SRG-APP-000080-DB-000063
<GroupDescription></GroupDescription>Group -
All installation-delivered IDMS DCADMIN-level tasks must be properly secured.
<VulnDiscussion>If DC Administrator-level tasks are not secured, any user logged on to IDMS may use them to access and manipulate various res...Rule Medium Severity -
SRG-APP-000033-DB-000084
<GroupDescription></GroupDescription>Group -
IDMS must protect against the use of default userids.
<VulnDiscussion>Default sign-ons can be used by individuals to perform adverse actions anonymously.</VulnDiscussion><FalsePositives&...Rule Low Severity -
SRG-APP-000080-DB-000063
<GroupDescription></GroupDescription>Group -
All installation-delivered IDMS User-level programs must be properly secured.
<VulnDiscussion>If user-level programs are not secured, then unauthorized users may use them to access and manipulate various resources withi...Rule Medium Severity -
SRG-APP-000033-DB-000084
<GroupDescription></GroupDescription>Group -
All installation-delivered IDMS Developer-level Programs must be properly secured.
<VulnDiscussion>Developer-level programs that are not secured may allow unauthorized users to access and manipulate various resources within ...Rule Medium Severity -
SRG-APP-000033-DB-000084
<GroupDescription></GroupDescription>Group -
All installation-delivered IDMS Database-Administrator-level programs must be properly secured.
<VulnDiscussion>DBA-level programs that are not secured may allow unauthorized users to use them to access and manipulate various resources w...Rule Medium Severity -
SRG-APP-000033-DB-000084
<GroupDescription></GroupDescription>Group -
SRG-APP-000001-DB-000031
<GroupDescription></GroupDescription>Group -
For interactive sessions, IDMS must limit the number of concurrent sessions for the same user to one or allow unlimited sessions.
<VulnDiscussion>Multiple interactive sessions can provide a way to cause a DoS attack against IDMS if a user ID and password were compromised...Rule Medium Severity -
SRG-APP-000023-DB-000001
<GroupDescription></GroupDescription>Group
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.