From Mainframe Product Security Requirements Guide
Part of SRG-APP-000353-MFP-000112
Associated with: CCI-001914
If authorized individuals do not have the ability to modify auditing parameters in response to a changing threat environment, the organization may not be able to effectively respond, and important forensic information may be lost.
Examine the installation and configuration settings. If system programmers do not have the capability to change auditing settings in accordance with applicable access control policies, this is a finding. If an external security manager (ESM) is used, check the ESM rules and configuration. If there are no rules for these resources or the rules do not allow update and above access to system programmers in accordance with applicable access control policies, this is a finding.
Configure the Mainframe Product to allow system programmers the capability to change auditing settings. This can be accomplished by using the ESM. Configure the ESM to allow update and above access to system programmers.
Lavender hyperlinks in small type off to the right (of CSS
class id
, if you view the page source) point to
globally unique URIs for each document and item. Copy the
link location and paste anywhere you need to talk
unambiguously about these things.
You can obtain data about documents and items in other
formats. Simply provide an HTTP header Accept:
text/turtle
or
Accept: application/rdf+xml
.
Powered by sagemincer