CA IDMS Security Technical Implementation Guide
Rules, Groups, and Values defined within the XCCDF Benchmark
-
IDMS must protect its user catalogs and system dictionaries to prevent unauthorized users from bypassing or updating security settings.
<VulnDiscussion>Unauthorized access to user profiles, dictionaries, and user catalogs provides the ability to damage the IDMS system.</Vul...Rule Medium Severity -
SRG-APP-000342-DB-000302
<GroupDescription></GroupDescription>Group -
IDMS must restrict the use of code that provides elevated privileges to specific instances.
<VulnDiscussion>When a user has elevated privileges, they may be able to deliberately or inadvertently make alterations to the DBMS structure...Rule Medium Severity -
SRG-APP-000380-DB-000360
<GroupDescription></GroupDescription>Group -
All installation-delivered IDMS DEVELOPER-level tasks must be properly secured.
<VulnDiscussion>Developer-level tasks that are not secured may allow anyone who signs on to IDMS to use them to access and manipulate various...Rule Medium Severity -
SRG-APP-000033-DB-000084
<GroupDescription></GroupDescription>Group -
All installation-delivered IDMS DBADMIN-level tasks must be properly secured.
<VulnDiscussion>DBA-level tasks that are not secured may allow anyone who signs on to IDMS to use them to access and manipulate various resou...Rule Medium Severity -
SRG-APP-000033-DB-000084
<GroupDescription></GroupDescription>Group -
All installation-delivered IDMS Database-Administrator-level programs must be properly secured.
<VulnDiscussion>DBA-level programs that are not secured may allow unauthorized users to use them to access and manipulate various resources w...Rule Medium Severity -
SRG-APP-000033-DB-000084
<GroupDescription></GroupDescription>Group -
All installation-delivered IDMS DCADMIN-level tasks must be properly secured.
<VulnDiscussion>If DC Administrator-level tasks are not secured, any user logged on to IDMS may use them to access and manipulate various res...Rule Medium Severity -
SRG-APP-000033-DB-000084
<GroupDescription></GroupDescription>Group -
All installation-delivered IDMS User-level programs must be properly secured.
<VulnDiscussion>If user-level programs are not secured, then unauthorized users may use them to access and manipulate various resources withi...Rule Medium Severity -
SRG-APP-000033-DB-000084
<GroupDescription></GroupDescription>Group -
CA IDMS must limit use of IDMS server used in issuing dynamic statements from client applications circumstances determined by the organization.
<VulnDiscussion>Server tasks can execute dynamic SQL code and should be protected.</VulnDiscussion><FalsePositives></FalsePosi...Rule Medium Severity -
SRG-APP-000251-DB-000392
<GroupDescription></GroupDescription>Group -
SRG-APP-000033-DB-000084
<GroupDescription></GroupDescription>Group -
SRG-APP-000296-DB-000306
<GroupDescription></GroupDescription>Group -
SRG-APP-000340-DB-000304
<GroupDescription></GroupDescription>Group -
All installation-delivered IDMS USER-level tasks must be properly secured.
<VulnDiscussion>User-level tasks that are not secured may allow anyone who signs on to IDMS to use them to access and manipulate various reso...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.