U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

zOS ACF2 STIG Version 6, Release 58 Checklist Details (Checklist Revisions)

Supporting Resources:

Target:

Target CPE Name
IBM OS390 cpe:/o:ibm:os_390 (View CVEs)

Checklist Highlights

Checklist Name:
zOS ACF2 STIG
Checklist ID:
287
Version:
Version 6, Release 58
Type:
Compliance
Review Status:
Final
Authority:
Governmental Authority: Defense Information Systems Agency
Original Publication Date:
04/28/2017

Checklist Summary:

This SRR Review Procedures, OS/390 Access Control Facility 2 (ACF2) document provides the procedures for conducting a Security Readiness Review (SRR) to determine compliance with the requirements in the OS/390 Security Technical Implementation Guides (STIG). This SRR guide focuses strictly on the IBM OS/390 operating system (OS) and how the ACF2 security component interacts with the operating system. Additionally, this checklist ensures the site has properly installed and implemented the ACF2 component for the IBM OS/390 OS and that it is being managed in a way that is secure, efficient, and effective, through procedures outlined in the checklist. The items reviewed are based on standards and requirements published by DISA in the OS/390 Security Technical Implementation Guide.

Checklist Role:

  • Mainframe Operating System

Known Issues:

Not provided.

Target Audience:

Developed for the DOD. This checklist has been created for IT professionals, particularly Information Assurance Managers (IAM), Information Assurance Officers (IAO/SA), Network Security Officers (NSO), and System Administrators (SAs) in support of protecting DoD Virtual Computing systems.

Target Operational Environment:

  • Managed
  • Specialized Security-Limited Functionality (SSLF)

Testing Information:

Not provided.

Regulatory Compliance:

DOD Directive 8500.

Comments/Warnings/Miscellaneous:

Not provided.

Disclaimer:

Not provided.

Product Support:

It should be noted that FSO Support for the STIGs, Checklists, and Tools is only available to DOD Customers.

Point of Contact:

disa.stig_spt@mail.mil

Sponsor:

Not provided.

Licensing:

Not provided.

Change History:

Version 6, Release 16 - 23 July 2013
Version 6, Release 15 - 26 April 2013
Version 6, Release 14 - 25 January 2013
Version 6, Release 13 - 26 October 2012
Version 6, Release 12 - 27 July 2012
Version 6, Release 11 - 27 April 2012
Version 6, Release 10 - 23 January 2012
Version 6, Release 9 - 28 October 2011
Version 6, Release 8 - 28 July 2011
Version 6, Release 7 - 29 April 2011
Version 6, Release 6 - 28 January 2011
Version 6, Release 5 - 29 October 2010
Version 6, Release 4 - 27 August 2010
Version 6, Release 3 - 23 April 2010
Version 6, Release 8 - 28 July 2011
Version 6, Release 21 - 04 November 2014
Updated status to "Final" - 07 January 2015
Updated "Point of Contact" - 07 January 2015
Version 6, Release 25 - 30 October 2015
Changed status from "Under Review" to "Final" - 29 December 2015
Version 6, Release 26 - 9 February 2016
3/15/2016 - Promote to Final
5/2/2016 - Version 6, Release 27
moved to FINAL - 6/7/2016
updated to - v6, r28 - 07/22/2016
Updated to FINAL - 09/12/2016
Updated STIG to Version 6, Release 29 - 10/28/2016
updated to FINAL - 12/07/2016
Updated to Ver 6, Rel 30 - 01/27/2017
Updated to FINAL - 03/13/2017
Updated to Version 6, Release 31 - 04/28/2017
Updated to FINAL - 05/30/2017
null
Updated URL to reflect change to the DISA website - http --> https
Updated - 11/01/2017
Updated to FINAL - 12/02/2017
Updated to v6, r34 - 12/18/2017
Update to FINAL - 1/23/18
Updated to Version 6, Release 35 - 02/16/2018
Updated to FINAL - 3/18/2018
updated to Ver 6, Rel 36 - 4/25/18
Updated to FINAL - 5/25/18
updated to Version 6, Release 37- 7/24/18
Updated to FINAL - 8/24/18
Updated to Version 6, Release 38 - 10/25/18
Updated to FINAL - 11/26/18
Updated to Version 6, Release 39 - 1/23/19
Updated to FINAL - 2/19/19
updated to Version 6, Release 40 - 4/30/19
Updated URLs - 6/14/19
Updated URLs - 8/12/2019
updated URLs - 11/1/19
updated URLs per DISA - 1/21/2020
updated per DISA - 3/3/2020
Updated URLs per DISA - 4/24/2020
Updated URLs - 8/3/2020
updated per DISA - 8/4/2020
updated URLs - 10/27/2020
updated URLs per DISA - 1/26/2021
Updated resources per DISA - 4/29/21
null
updated URLs - 7/28/2021
updated SHA - 8/6/2021
updated URLs - 10/29/2021
updated URLs - 1/26/2022
updated URLs - 4/25/2022
Updated resource per DISA - 8/1/22
null
Updated resource per DISA - 10/26/22
Updated resource per DISA - 10/27/22
updated URLs - 11/15/2022
updated URLs per DISA - 1/17/2023
updated URLs - 2/6/2023
Updated resource per DISA - 4/28/23
Updated URLs per DISA - 7/25/23
Updated resource per DISA - 10/26/23
Updated resource per DISA - 10/26/23
updated URLs - 1/29/24

Dependency/Requirements:

URL Description
https://dl.dod.cyber.mil/wp-content/uploads/stigs/pdf/zos_stig_v6r1.1memo080609.pdf zOS STIG Memo - Ver 6, Rel 1.1

References:

Reference URL Description

NIST checklist record last modified on 01/29/2024