z/OS ACF2 STIG Compliance Checklist
15 items · Security · Hard difficulty · 4 hours
Step-by-step STIG checklist to secure IBM z/OS with ACF2.
-
Download latest z/OS ACF2 STIG and XCCDF from DISA
Grab the Standalone XCCDF and STIG resources from DISA.
-
Verify STIG version matches organizational baseline
Confirm version (e.g., Y26M01) and record it in inventory.
-
Identify target systems running IBM z/OS
List hostnames, LPARs, and system IDs to scope the review.
-
Gather system inventory and configuration files
Collect SMF, ACF2 configs, SYS1 datasets and change logs.
-
Ensure ACF2 product is installed and versioned
Confirm ACF2 presence and supported release on each target.
-
Confirm ACF2 integration with z/OS security services
Verify interfaces with LDAP, logging, and system auth services.
-
Run automated STIG scan using provided XCCDF tools
Use SCAP/XCCDF tools to perform baseline assessment.
-
Configure scanner with target CPE and credentials
Set the correct CPE name and use service accounts with read access.
-
Execute scan and save results
Run the scan and export reports (XML/CSV) for review.
-
Review scan findings and prioritize vulnerabilities
Flag critical/high findings for immediate remediation.
-
Remediate high-risk findings per STIG guidance
Apply configuration changes following the STIG ruleset.
-
Document configuration changes and approvals
Record change tickets, approvals, and rollback procedures.
-
Validate remediations with follow-up scan
Re-scan affected systems to confirm fixes and capture evidence.
-
Update system baseline and change control records
Incorporate approved configurations into the official baseline.
-
Schedule regular STIG compliance scans and reviews
Define cadence and owners for ongoing compliance checks.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.