STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← Back to STIGs

z/OS IBM CICS Transaction Server for RACF Security Technical Implementation Guide

Version

V7R2

Release Date

Sep 27, 2025

SCAP Benchmark ID

zOS_IBM_CICS_Transaction_Server_for_RACF

Total Checks

9

Tags

other
CAT I: 0CAT II: 9CAT III: 0

This Security Technical Implementation Guide is published as a tool to improve the security of Department of Defense (DOD) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via email to the following address: disa.stig_spt@mail.mil.

Export CKLExport CSVExport JSONDownload STIG ZIP

Checks (9)

V-224492MEDIUMCICS system data sets are not properly protected.V-224493MEDIUMSensitive CICS transactions are not protected in accordance with security requirements.V-224494MEDIUMCICS System Initialization Table (SIT) parameter values must be specified in accordance with proper security requirements.V-224495MEDIUMCICS region logonid(s) must be defined and/or controlled in accordance with the security requirements.V-224496MEDIUMCICS default logonid(s) must be defined and/or controlled in accordance with the security requirements.V-224497MEDIUMCICS logonid(s) must have timeout limit set to 15 minutes.V-224498MEDIUMIBM CICS Transaction Server SPI command resources must be properly defined and protected.V-224499MEDIUMExternal RACF Classes are not active for CICS transaction checking.V-224500MEDIUMCICS regions are improperly protected to prevent unauthorized propagation of the region userid.