Skip to content

All installation-delivered IDMS DCADMIN-level tasks must be properly secured.

An XCCDF Rule

Description

If DC Administrator-level tasks are not secured, any user logged on to IDMS may use them to access and manipulate various resources within the DBMS. This can be mitigated using the proper entries in the SRTT. Satisfies: SRG-APP-000033-DB-000084, SRG-APP-000211-DB-000122

ID
SV-251589r960792_rule
Version
IDMS-DB-000090
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

The SRTT module must be coded to enable task-level security. When using an ESM, this could be done in the following manner:
 
#SECRTT TYPE=ENTRY,                          X
 RESTYPE=TASK,                                     X
 SECBY=EXTERNAL ,                               X
 EXTNAME=(RESTYPE,RESNAME),        X