STIGQter STIGQter: STIG Summary: IBM z/OS ACF2 Security Technical Implementation Guide Version: 8 Release: 2 Benchmark Date: 23 Apr 2021:

ACF2 emergency LOGONIDS with the REFRESH attribute must have the SUSPEND attribute specified.

DISA Rule

SV-223486r533198_rule

Vulnerability Number

V-223486

Group Title

SRG-OS-000480-GPOS-00227

Rule Version

ACF2-ES-000680

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

The emergency logonids with the REFRESH attribute must be in SUSPEND status unless actually in use.

Example:
SET LID
CHANGE logonid SUSPEND

Check Contents

From the ACF Command screen enter:
SET LID
LIST IF(REFRESH)

If the logonid is an emergency logonid and the REFRESH attribute is not in SUSPEND status, this is a finding.

Vulnerability Number

V-223486

Documentable

False

Rule Version

ACF2-ES-000680

Severity Override Guidance

From the ACF Command screen enter:
SET LID
LIST IF(REFRESH)

If the logonid is an emergency logonid and the REFRESH attribute is not in SUSPEND status, this is a finding.

Check Content Reference

M

Target Key

4100

Comments