z/OS TSS STIG (Y26M01) SRR Compliance Checklist
19 items · Security · Hard difficulty · 2 hours
SRR-focused z/OS Top Secret compliance checklist for admins and IA teams.
-
Download STIG XCCDF and SRR script resources
Get standalone XCCDFs for z/OS STIG, TSS products, and SRR scripts from DISA.
-
Verify STIG version equals Y26M01 and record release info
Confirm checklist ID/version matches site policy before testing.
-
Validate SHA256 checksums for downloaded files
Confirm file integrity before using XCCDF or scripts.
-
Inventory IBM z/OS systems that run Top Secret
List hostnames, LPARs, system versions, and owners.
-
Confirm Top Secret product is installed on each target
Verify product IDs, levels, and installation status per system.
-
Verify Top Secret configuration matches STIG requirements
Compare system settings to STIG controls; document deviations.
-
Enforce password and session policies per STIG
Check password complexity, expiration, lockout, and idle time.
-
Disable or remove default and unused accounts
Identify and secure or remove service/default accounts.
-
Restrict and audit privileged roles and access
Validate separation of duties and approval for privileged IDs.
-
Disable unnecessary services and network interfaces
Shut down services not required for operation or management.
-
Implement and verify access control lists and profiles
Ensure authorized profiles and ACLs follow least privilege.
-
Enable detailed logging and forward logs to SIEM
Configure audit logging and secure forwarding to central SIEM.
-
Ensure audit trails are retained per DOD policy
Verify retention periods, storage, and tamper protection.
-
Review recent audit logs for suspicious activity
Search for privilege escalations, failed auths, and anomalies.
-
Apply latest security patches to z/OS and Top Secret
Confirm system is at approved patch level and vendor fixes applied.
-
Verify backup and recovery procedures include security configs
Test restore of Top Secret configs and STIG-related data.
-
Securely store and rotate cryptographic keys and credentials
Use HSMs/secure vaults and document rotation schedules.
-
Collect and save SRR evidence and supporting documentation
Capture screenshots, config files, XCCDF results, and notes.
-
Contact DISA point of contact for STIG support or issues
Use the provided DISA POC for questions or to report noncompliance.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.