STIGQter STIGQter: STIG Summary: IBM z/OS ACF2 Security Technical Implementation Guide Version: 8 Release: 2 Benchmark Date: 23 Apr 2021:

ACF2 LOGONIDs must be defined with the required fields completed.

DISA Rule

SV-223496r533198_rule

Vulnerability Number

V-223496

Group Title

SRG-OS-000104-GPOS-00051

Rule Version

ACF2-ES-000780

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Define every user to ACF2 with a unique userid. (ACF2 calls this a logonid.) To ACF2, a user is an individual, a started task, or a batch job.

Every user will be fully identified within ACF2. Complete the following fields for every logonid:

NAME - User's name
UID-String - All fields defined in the ACFFDR @UID macro

All fields that comprise the standard UID string will be filled out for each user as a logonid is added.

Example:
SET LID
INSERT logonid UID(uid string) NAME(user name)

Check Contents

From an ACF Command Screen enter:
SET LID
LIST *

If the below listed fields are complete for all logonids, this is not a finding.

NAME User's name
UID-String All fields defined in the ACFFDR @UID macro

NOTE: A completed NAME field that can either be traced back to a current DD Form 2875 or a Vendor Requirement (example: A Started Task).

NOTE: A user may be required to have more than one logonid but users must not share userids.

Vulnerability Number

V-223496

Documentable

False

Rule Version

ACF2-ES-000780

Severity Override Guidance

From an ACF Command Screen enter:
SET LID
LIST *

If the below listed fields are complete for all logonids, this is not a finding.

NAME User's name
UID-String All fields defined in the ACFFDR @UID macro

NOTE: A completed NAME field that can either be traced back to a current DD Form 2875 or a Vendor Requirement (example: A Started Task).

NOTE: A user may be required to have more than one logonid but users must not share userids.

Check Content Reference

M

Target Key

4100

Comments