SV-223626r1225849_rule
V-223626
SRG-OS-000080-GPOS-00048
ACF2-US-000110
CAT II
10
Define the STEPLIBLIST with update and allocate access to libraries residing in the /etc/steplib limited to systems programmers only.
The STEPLIBLIST parameter specifies the pathname of the HFS file that contains the list of MVS data sets used as step libraries for programs that have the set-user-id or set group id permission bit set.
The use of STEPLIBLIST is at the site's discretion, but if used, the value of STEPLIBLIST will be /etc/steplib. All WRITE and ALLOCATE access to the MVS data sets in the list will be logged and only systems programming personnel will be authorized to update the data sets.
Refer to the STEPLIBLIST statement in the BPXPRMxx member of PARMLIB.
If the STEPLIBLIST points to an etc/steplib, go to the ISPF Command Shell and enter:
OMVS
cd /etc
cat <filename>
If the ESM data set rules for libraries specified in the STEPLIBLIST file do not restrict WRITE and/or ALLOCATE access to only systems programming personnel, this is a finding.
If the ESM data set rules for libraries specified in the STEPLIBLIST file do not specify that all (i.e., failures and successes) WRITE and/or ALLOCATE access will be logged, this is a finding.
V-223626
False
ACF2-US-000110
Refer to the STEPLIBLIST statement in the BPXPRMxx member of PARMLIB.
If the STEPLIBLIST points to an etc/steplib, go to the ISPF Command Shell and enter:
OMVS
cd /etc
cat <filename>
If the ESM data set rules for libraries specified in the STEPLIBLIST file do not restrict WRITE and/or ALLOCATE access to only systems programming personnel, this is a finding.
If the ESM data set rules for libraries specified in the STEPLIBLIST file do not specify that all (i.e., failures and successes) WRITE and/or ALLOCATE access will be logged, this is a finding.
M
4100