Skip to content

The Mainframe Product must transmit only cryptographically protected passwords.

An XCCDF Rule

Description

Passwords need to be protected at all times and encryption is the standard method for protecting passwords. If passwords are not encrypted, they can be plainly read (i.e., clear text) and easily compromised. Applications can accomplish this by making direct function calls to encryption modules or by leveraging operating system encryption capabilities.

ID
SV-205502r961029_rule
Version
SRG-APP-000172-MFP-000234
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Configure the Mainframe Product account management to transmit only cryptographically protected passwords.