Hi

 

I have been given some question by security auditors and I am having
trouble tracking the answers down. I was wondering if anyone could help
me with the answers to the following. This is what they are asking for:

 

(5)  Please print the configuration of the CP (zVM OS) to indicate the
following:

 

5-1.  RACF is configured to be the external security manager (ESM) of
zVM.

 

5-2.  Configuration of zVM internal auditing:  if RACF is not configured
to capture zVM security events, is CP configured to log specific
security event?

 

5-3.  Is zVM configured to overwrite the temporary (T) disk upon
allocation to prevent unauthorized access to sensitive data placed on
T-disks.

 

5-4.  Object reuse parameter settings supported/configured for CP to
minimize unauthorized users accessing sensitive CMS residual data (i.e.,
data deleted but not scratched from minidisk space).

 

 

Thank You,

 

Terry Martin

Lockheed Martin - Information Technology

z/OS & z/VM Systems - Performance and Tuning

Cell - 443 632-4191

Work - 410 786-0386

terry.mar...@cms.hhs.gov

 

WFH on Tuesdays and Fridays

 

Reply via email to