STIGQter STIGQter: STIG Summary: IBM z/OS ACF2 Security Technical Implementation Guide Version: 8 Release: 2 Benchmark Date: 23 Apr 2021:

CA-ACF2 RULEOPTS GSO record values must be set to the values specified.

DISA Rule

SV-223475r695416_rule

Vulnerability Number

V-223475

Group Title

SRG-OS-000480-GPOS-00227

Rule Version

ACF2-ES-000570

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the GSO RULEOPTS record values to conform to the following requirements.

NO$NOSORT
CENTRAL
CHANGE
DECOMP(AUDIT SECURITY) | DECOMP(AUDIT) | DECOMP(SECURITY)

The other RULEOPTS values should be assigned carefully as they affect the Rules and Infostorage databases.

Example:
SET C(GSO)
INSERT RULEOPTS NO$NOSORT CENTRAL CHANGE NOCOMPDYN DECOMP(AUDIT SECURITY)
F ACF2,REFRESH(RULEOPTS)

Check Contents

From the ACF Command enter:
SET CONTROL(GSO)
LIST RULEOPTS

If the following options are defined, this is not a finding.

NO$NOSORT
CENTRAL
CHANGE
DECOMP(AUDIT SECURITY) | DECOMP(AUDIT) | DECOMP(SECURITY)

The other RULEOPTS values should be assigned carefully as they affect the Rules and Infostorage databases.

Vulnerability Number

V-223475

Documentable

False

Rule Version

ACF2-ES-000570

Severity Override Guidance

From the ACF Command enter:
SET CONTROL(GSO)
LIST RULEOPTS

If the following options are defined, this is not a finding.

NO$NOSORT
CENTRAL
CHANGE
DECOMP(AUDIT SECURITY) | DECOMP(AUDIT) | DECOMP(SECURITY)

The other RULEOPTS values should be assigned carefully as they affect the Rules and Infostorage databases.

Check Content Reference

M

Target Key

4100

Comments