STIGQter STIGQter: STIG Summary: z/OS RACF STIG Version: 6 Release: 43 Benchmark Date: 24 Jan 2020: z/OS UNIX SUPERUSER resource must be protected in accordance with guidelines.

DISA Rule

SV-19748r3_rule

Vulnerability Number

V-6972

Group Title

ZUSS0023

Rule Version

ZUSS0023

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Ensure that all SUPERUSER resources for the UNIXPRIV resource class are restricted to appropriate system tasks and/or system programming personnel.

1) The RACF rules for the SUPERUSER resource specify a default access of NONE.

2) There are no RACF rules that allow access to the SUPERUSER resource.

3) There is no RACF rule for CHOWN.UNRESTRICTED defined.

4) The RACF rules for each of the SUPERUSER resources listed in the UNIXPRIV CLASS RESOURCES Table in the z/OS STIG Addendum, specify a default access of NONE.

5) The RACF rules for each of the SUPERUSER resources listed in the UNIXPRIV CLASS RESOURCES Table in the z/OS STIG Addendum, restrict access to appropriate system tasks or systems programming personnel.

Sample Commands:

RDEF UNIXPRIV SUPERUSER.** UACC(NONE) OWNER(ADMIN) DATA('REFERENCE ZUSS0023') AUDIT(ALL(READ))
/* do not permit any users/groups to this resource */

SR CLASS(UNIXPRIV) MASK(CHOWN.UNRESTRICTED)
/* delete if found */

PE SUPERUSER.FILESYS.** CL(UNIXPRIV) ID(<SYSPAUDT>)
/* where SUPERUSER.FILESYS.** represents one of the resources listed in the UNIXPRIV CLASS RESOURCES table in the Addendum */

Check Contents

a) Refer to the following report produced by the Data Set and Resource Data Collection:

- SENSITVE.RPT(UNIXPRIV)

Automated Analysis
Refer to the following report produced by the Data Set and Resource Data Collection:

- PDI(ZUSS0023)

b) Review the following items for the UNIXPRIV resource class:

1) The RACF rules for the SUPERUSER resource specify a default access of NONE.
2) There are no RACF rules that allow access to the SUPERUSER resource.
3) There is no RACF rule for CHOWN.UNRESTRICTED defined.
4) The RACF rules for each of the SUPERUSER resources listed in the UNIXPRIV CLASS RESOURCES Table in the z/OS STIG Addendum, specify a default access of NONE.
5) The RACF rules for each of the SUPERUSER resources listed in the UNIXPRIV CLASS RESOURCES Table in the z/OS STIG Addendum, restrict access to appropriate system tasks or systems programming personnel.

c) If any item in (b) is untrue, this is a FINDING.

d) If all items in (b) are true, this is NOT A FINDING.

Vulnerability Number

V-6972

Documentable

False

Rule Version

ZUSS0023

Severity Override Guidance

a) Refer to the following report produced by the Data Set and Resource Data Collection:

- SENSITVE.RPT(UNIXPRIV)

Automated Analysis
Refer to the following report produced by the Data Set and Resource Data Collection:

- PDI(ZUSS0023)

b) Review the following items for the UNIXPRIV resource class:

1) The RACF rules for the SUPERUSER resource specify a default access of NONE.
2) There are no RACF rules that allow access to the SUPERUSER resource.
3) There is no RACF rule for CHOWN.UNRESTRICTED defined.
4) The RACF rules for each of the SUPERUSER resources listed in the UNIXPRIV CLASS RESOURCES Table in the z/OS STIG Addendum, specify a default access of NONE.
5) The RACF rules for each of the SUPERUSER resources listed in the UNIXPRIV CLASS RESOURCES Table in the z/OS STIG Addendum, restrict access to appropriate system tasks or systems programming personnel.

c) If any item in (b) is untrue, this is a FINDING.

d) If all items in (b) are true, this is NOT A FINDING.

Check Content Reference

M

Responsibility

Systems Programmer

Target Key

197

Comments