Hi, we're looking at migrating to using the STIG standards as a baseline for our compliance on our ACF2 and RACF mainframes, and using zSecure to perform the compliance checks. We are currently running zSecure 2.4 with plans to migrate to version 2.5 by years end. When looking at the lastest versions of the STIG documents, I noted that the STIG rule names in zSecure don't map to the RuleID in the STIG documents. I was wondering if there is a matrix or document that can help us map the rules in the official STIG documents to the defined STIG checks in zSecure?
Example:
ZSecure 2.4 Check:
Rule Standard Description Member
RACF0244 STIG FACILITY class active CKAGR244
STIG 8.10 Entry:
Vul ID: V-223657 Rule ID: SV-223657r604139_rule STIG ID: RACF-ES-000090 Rule Title: The IBM RACF FACILITY resource class must be active.
My understanding is the current version of the z/OS STIGs for RACF and ACF2 is 8.10 and that zSecure 2.4 supported STIG version 6.41, so I realise there will be some discrepancies. Thanks very much for any assistance you can provide, sorry if I have missed something obvious.
------------------------------
Nathan Shrive
------------------------------