STIGQter STIGQter: STIG Summary: IBM z/OS ACF2 Security Technical Implementation Guide Version: 8 Release: 2 Benchmark Date: 23 Apr 2021:

IBM z/OS TSO GSO record values must be set to the values specified.

DISA Rule

SV-223469r533198_rule

Vulnerability Number

V-223469

Group Title

SRG-OS-000480-GPOS-00227

Rule Version

ACF2-ES-000510

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the GSO TSO record values to conform to the following requirements.

ACCOUNT(1)
BYPASS(#)
CHAR(BS)
CMDLIST()
NOIKJEFLD1
LINE(ATTN)
LOGONCK
PERFORM(0)
PROC(site defined)
NOQLOGON
REGION(site defined)
SUBCLSS()
SUBHOLD()
SUBMSGC()
TIME(0)
TSOSOUT(A)
UNIT(SYSDA)
WAITIME(1-60)

Example:
SET C(GSO)
INSERT TSO ACCOUNT(1) BYPASS(#) CHAR(BS) CMDLIST() NOIKJEFLD1 LINE(ATTN) LOGONCK PERFORM(0) PROC(IKJACCNT) NOQLOGON REGION(4,096) SUBCLSS() SUBHOLD() SUBMSGC() TIME(0) TSOGNAME() TSOSOUT(A) UNIT(SYSDA) WAITIME(60)

F ACF2,REFRESH(TSO)

Check Contents

From the ACF Command screen enter:
SET CONTROL(GSO)
LIST TSO

If the GSO TSO record values conform to the following requirements, this is not a finding.

ACCOUNT(1)
BYPASS(#)
CHAR(BS)
CMDLIST()
NOIKJEFLD1
LINE(ATTN)
LOGONCK
PERFORM(0)
PROC(site defined)
NOQLOGON
REGION(site defined)
SUBCLSS()
SUBHOLD()
SUBMSG()
TIME(0)
TSOSOUT(A)
UNIT(SYSDA)
WAITIME(1-60)

Vulnerability Number

V-223469

Documentable

False

Rule Version

ACF2-ES-000510

Severity Override Guidance

From the ACF Command screen enter:
SET CONTROL(GSO)
LIST TSO

If the GSO TSO record values conform to the following requirements, this is not a finding.

ACCOUNT(1)
BYPASS(#)
CHAR(BS)
CMDLIST()
NOIKJEFLD1
LINE(ATTN)
LOGONCK
PERFORM(0)
PROC(site defined)
NOQLOGON
REGION(site defined)
SUBCLSS()
SUBHOLD()
SUBMSG()
TIME(0)
TSOSOUT(A)
UNIT(SYSDA)
WAITIME(1-60)

Check Content Reference

M

Target Key

4100

Comments