ACF2 SECVOLS GSO record value must be set to VOLMASK(). Any local changes are justified and documented with the ISSO.
An XCCDF Rule
Description
The SECVOLS record defines the DASD and tape volumes for which CA-ACF2 provides volume-level protection. Information at rest refers to the state of information when it is located on a secondary storage device (e.g., disk drive and tape drive, when used for backups) within an operating system. This requirement addresses protection of user-generated data, as well as operating system-specific configuration data. Organizations may choose to employ different mechanisms to achieve confidentiality and integrity protections, as appropriate, in accordance with the security category and/or classification of the information.
- ID
- SV-223512r958552_rule
- Version
- ACF2-ES-000950
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Define the GSO SECVOLS record values to conform to the following requirements.
VOLMASK()
Example:
SET C(GSO)