U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

z/OS RACF STIG Version 6, Release 62 Checklist Details (Checklist Revisions)

Supporting Resources:

Target:

Target CPE Name
IBM OS390 cpe:/o:ibm:os_390 (View CVEs)

Checklist Highlights

Checklist Name:
z/OS RACF STIG
Checklist ID:
55
Version:
Version 6, Release 62
Type:
Compliance
Review Status:
Final
Authority:
Governmental Authority: Defense Information Systems Agency
Original Publication Date:
04/28/2017

Checklist Summary:

This SRR Review Procedures, OS/390 Resource Access Control Facility (RACF) document provides the procedures for conducting a Security Readiness Review (SRR) to determine compliance with the requirements in the OS/390 Security Technical Implementation Guides (STIG). This checklist must be used together with the corresponding version of the STIG document. This SRR guide focuses strictly on the IBM OS/390 operating system (OS) and how the RACF security component interacts with the operating system. Additionally, this checklist ensures the site has properly installed and implemented the RACF component for the IBM OS/390 OS and that it is being managed in a way that is secure, efficient, and effective, through procedures outlined in the checklist. The items reviewed are based on standards and requirements published by DISA in the OS/390 Security Technical Implementation Guide.

Checklist Role:

  • Mainframe Operating System

Known Issues:

Not provided.

Target Audience:

Developed for the DOD. This checklist has been created for IT professionals, particularly operating system administrators with a background in the IBM OS/390 OS, as well as information security personnel. The document assumes that the reader has experience installing and administering the IBM OS/390-based systems in domain or standalone configurations.

Target Operational Environment:

  • Managed
  • Specialized Security-Limited Functionality (SSLF)

Testing Information:

Not provided.

Regulatory Compliance:

DOD Directive 8500.

Comments/Warnings/Miscellaneous:

Please refer to the Checklist or the README.txt files provided with the scripts for any comments, warnings, or detailed instructions.

Disclaimer:

Not provided.

Product Support:

It should be noted that FSO Support for the STIGs, Checklists, and Tools is only available to DOD Customers.

Point of Contact:

disa.stig_spt@mail.mil

Sponsor:

Not provided.

Licensing:

Not provided.

Change History:

Version 6, Release 16 - 23 July 2013
Version 6, Release 15 - 26 April 2013
Version 6, Release 14 - 25 January 2013
Version 6, Release 13 - 26 October 2012
Version 6, Release 12 - 27 July 2012
Version 6, Release 11 - 27 April 2012
Version 6, Release 10 - 23 January 2012
Version 6, Release 9 - 28 October 2011
Version 6, Release 8 - 28 July 2011
Version 6, Release 7 - 29 April 2011
Version 6, Release 6 - 28 January 2011
Version 6, Release 5 - 29 October 2010
Version 6, Release 4 - 27 August 2010
Version 6, Release 3 - 23 April 2010
Version 6, Release 8 - 28 July 2011
1/26/2012- updated target audience section to read "developed for the DoD" vs. "Developped for the DoD"
Version 6, Release 21 - 04 November 2014
Added point of contact
Changed Status from "Under Review" to "Final" - 18 February 2015
Version 6, Release 25 - 30 October 2015
Changed status from "Under Review" to "Final" - 29 December 2015
Version 6, Release 26 - 9 February 2016
3/15/2016 - Promote to Final
5/2/2016 - Version 6, Release 27
moved to FINAL - 6/7/2016
updated to - v6, r28 - 07/22/2016
Updated to FINAL - 09/12/2016
Updated STIG to Version 6, Release 29 - 10/28/2016
updated to FINAL - 12/07/2016
Updated to Ver 6, Rel 30 - 01/27/2017
Updated to FINAL - 03/13/2017
Updated to Version 6, Release 31 - 04/28/2017
Updated to FINAL - 05/30/2017
null
Updated URL to reflect change to the DISA website - http --> https
Updated - 11/01/2017
Updated to FINAL - 12/02/2017
Updated to v6, r34 - 12/18/2017
Update to FINAL - 1/23/18
Updated to Version 6, Release 35 - 02/16/2018
Updated to FINAL - 3/18/2018
updated to Ver 6, Rel 36 - 4/25/18
Updated to FINAL - 5/25/18
updated to Version 6, Release 37 - 7/24/18
Updated to FINAL - 8/24/18
Updated to Version 6, Release 38 - 10/25/18
Updated to FINAL - 11/26/18
Updated to Version 6, Release 39 - 1/23/19
Updated to FINAL - 2/19/19
updated to Version 6, Release 40 - 4/30/19
Updated URLs - 6/14/19
Updated URLs - 8/12/2019
updated URLs - 11/1/19
updated URLs per DISA - 1/21/2020
updated per DISA - 3/3/2020
Updated URLs per DISA - 4/24/2020
Updated URLs - 8/4/2020
updated URLs - 10/27/2020
updated URLs per DISA - 1/26/2021
Updated resources per DISA - 4/29/21
null
updated URLs - 7/28/2021
updated SHA - 8/6/2021
updated URLs - 10/29/2021
updated URLs - 1/26/2022
updated URLs - 4/25/2022
Updated resource per DISA - 8/1/22
Updated resource per DISA - 8/1/22
Updated resource per DISA - 10/26/22
Updated resource per DISA - 10/27/22
updated URLs - 11/15/2022
updated URLs per DISA - 1/17/2023
updated URLs - 2/6/2023
Updated resource per DISA - 4/27/23
updated URLs per DISA - 7/25/23
Updated resource per DISA - 10/26/23
Updated resource per DISA - 10/26/23
updated URLs - 1/29/24
Update Version and Resources - 06/10/2024
Updated Checklist Version, Resources and SHA - 08/12/2024
Updated Checklist Title and Resources - 08/13/2024
Resources, Title, and SHA Updated - 10/29/2024

Dependency/Requirements:

URL Description
https://dl.dod.cyber.mil/wp-content/uploads/stigs/pdf/zos_stig_v6r1.1memo080609.pdf zOS STIG Memo - Ver 6, Rel 1.1

References:

Reference URL Description

NIST checklist record last modified on 10/29/2024