STIGQter STIGQter: STIG Summary: IBM z/OS ACF2 Security Technical Implementation Guide Version: 8 Release: 2 Benchmark Date: 23 Apr 2021:

ACF2 maintenance LOGONIDs must have corresponding GSO MAINT records.

DISA Rule

SV-223481r695419_rule

Vulnerability Number

V-223481

Group Title

SRG-OS-000480-GPOS-00227

Rule Version

ACF2-ES-000630

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Ensure that an associated GSO maintenance record exists for each special user logonid identifying the program(s) that it is permitted to access and the library where the program(s) resides.

Define associated GSO MAINT record for each special user logonid, identifying the program(s) that it is permitted to access and the library where the program(s) resides.

Every maintenance logonid has a corresponding GSO MAINT record.

Example:

SET C(GSO)
INSERT MAINT.DFSMSHSM LIBRARY(SYS1.LINKLIB) LID(HSMDFDSS) PGM(ADRDSSU)

F ACF2,REFRESH(MAINT)

Check Contents

From the ACF Command screen enter:
SET LID
LIST IF(MAINT)

SET CONTROL(GSO)
LIST LIKE(MAINT-)

If every maintenance logonid has a corresponding GSO MAINT record, this is not a finding.

Vulnerability Number

V-223481

Documentable

False

Rule Version

ACF2-ES-000630

Severity Override Guidance

From the ACF Command screen enter:
SET LID
LIST IF(MAINT)

SET CONTROL(GSO)
LIST LIKE(MAINT-)

If every maintenance logonid has a corresponding GSO MAINT record, this is not a finding.

Check Content Reference

M

Target Key

4100

Comments