STIGQter STIGQter: STIG Summary: IBM z/OS ACF2 Security Technical Implementation Guide Version: 8 Release: 2 Benchmark Date: 23 Apr 2021:

IBM z/OS SYS1.PARMLIB must be properly protected.

DISA Rule

SV-223463r533198_rule

Vulnerability Number

V-223463

Group Title

SRG-OS-000063-GPOS-00032

Rule Version

ACF2-ES-000440

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure access rules for SYS1.PARMLIB as follows:
Systems programming personnel will be authorized to update and alter the SYS1.PARMLIB concatenation.
Domain level security administrators can be authorized to update the SYS1.PARMLIB concatenation.
System Level Started Tasks, authorized Data Center personnel, and auditor can be authorized read access by the ISSO.
All update and alter access is logged.

Check Contents

Execute a data set list of access to SYS1.PARMLIB.

If the ESM data set rules for SYS1.PARMLIB allow inappropriate (e.g., global READ) access.

If data set rules for SYS1.PARMLIB do not restrict READ, UPDATE, and ALTER access to only systems programming personnel, this is a finding.

If data set rules for SYS1.PARMLIB do not restrict READ and UPDATE access to only domain level security administrators, this is a finding.

If data set rules for SYS1.PARMLIB do not restrict READ access to only system Level Started Tasks, authorized Data Center personnel, and auditors, this is a finding.

If data set rules for SYS1.PARMLIB do not specify that all (i.e., failures and successes) UPDATE and/or ALTER access will be logged, this is a finding.

Vulnerability Number

V-223463

Documentable

False

Rule Version

ACF2-ES-000440

Severity Override Guidance

Execute a data set list of access to SYS1.PARMLIB.

If the ESM data set rules for SYS1.PARMLIB allow inappropriate (e.g., global READ) access.

If data set rules for SYS1.PARMLIB do not restrict READ, UPDATE, and ALTER access to only systems programming personnel, this is a finding.

If data set rules for SYS1.PARMLIB do not restrict READ and UPDATE access to only domain level security administrators, this is a finding.

If data set rules for SYS1.PARMLIB do not restrict READ access to only system Level Started Tasks, authorized Data Center personnel, and auditors, this is a finding.

If data set rules for SYS1.PARMLIB do not specify that all (i.e., failures and successes) UPDATE and/or ALTER access will be logged, this is a finding.

Check Content Reference

M

Target Key

4100

Comments