STIGQter STIGQter: STIG Summary: IBM z/OS ACF2 Security Technical Implementation Guide Version: 8 Release: 2 Benchmark Date: 23 Apr 2021:

IBM z/OS DFSMS control data sets must reside on separate storage volumes.

DISA Rule

SV-223559r533198_rule

Vulnerability Number

V-223559

Group Title

SRG-OS-000480-GPOS-00227

Rule Version

ACF2-OS-000230

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Allocate the primary and backup SMS Control data sets on separate volumes.

Source Control Data Set (SCDS) contains a SMS configuration, which defines a storage management policy.

Active Control Data Set (ACDS) contains a copy of the most recently activated configuration. All systems in a SMS complex use this configuration to manage storage.

Communications Data Set (COMMDS) contains the name of the ACDS containing the currently active storage management policy, the current utilization statistics for each system managed volume, and other system information.

The ACDS data set will reside on a different volume than the COMMDS data set.

Allocate backup copies of the ADCS and COMMDS data sets on a different shared volume from the primary ACDS and COMMDS data sets.

Check Contents

Review the logical parmlib data sets, example: SYS1.PARMLIB(IGDSMSxx), to identify the fully qualified file names for the following SMS data sets:
Active Control Data Set (ACDS)
Communications Data Set (COMMDS)

If the COMMDS and ACDS SMS data sets identified above reside on different volumes, this is not a finding.

If the COMMDS and ACDS SMS data sets identified above are collocated on the same volume, this is a finding.

Vulnerability Number

V-223559

Documentable

False

Rule Version

ACF2-OS-000230

Severity Override Guidance

Review the logical parmlib data sets, example: SYS1.PARMLIB(IGDSMSxx), to identify the fully qualified file names for the following SMS data sets:
Active Control Data Set (ACDS)
Communications Data Set (COMMDS)

If the COMMDS and ACDS SMS data sets identified above reside on different volumes, this is not a finding.

If the COMMDS and ACDS SMS data sets identified above are collocated on the same volume, this is a finding.

Check Content Reference

M

Target Key

4100

Comments