SV-223665r1195461_rule
V-223665
SRG-OS-000080-GPOS-00048
RACF-ES-000170
CAT II
10
Configure Global Access Checking to be appropriately administered.
Note: Special consideration should be followed as indicated in z/OS Security Server RACF Security Administrator's Guide.
Evaluate the impact associated with implementation of the control option. Develop approval documentation and a plan of action to implement the control option as specified in the example below:
RALT GLOBAL class-name
ADDMEM (resourcename)/accesslevel)
From a command input screen, enter:
RL Global *
If Global * is specified in SETROPTS, this is a finding.
The following entries may be allowed with the approval of the information system security manager (ISSM):
Dataset Class - ALTER access level to &RACUID.** (Allows users all access to their own datasets)
OPERCMDS Class - READ access to MVS.MCSOPER.&RACUID (Allows users access to console for their jobs)
JESJOBS Class - ALTER access to CANCEL.*.*.&RACUID (Allows users to cancel their own jobs)
JESJOBS Class - ALTER access to SUBMIT.*.*.&RACUID (Allows users to submit their own jobs)
The ISSM may allow other classes to be included after evaluation with the system programmer.
Note: Be careful when adding any resource requiring auditing to Global Access Checking. RACF performs no logging other than that requested by the SETROPTS LOGOPTIONS command. There are other special consideration for global access checking found in the z/OS Security Server RACF Security Administrator's Guide.
If any other members are included for Global Access Checking, this is a finding.
If written approval by the ISSM is not provided, this is a finding.
V-223665
False
RACF-ES-000170
From a command input screen, enter:
RL Global *
If Global * is specified in SETROPTS, this is a finding.
The following entries may be allowed with the approval of the information system security manager (ISSM):
Dataset Class - ALTER access level to &RACUID.** (Allows users all access to their own datasets)
OPERCMDS Class - READ access to MVS.MCSOPER.&RACUID (Allows users access to console for their jobs)
JESJOBS Class - ALTER access to CANCEL.*.*.&RACUID (Allows users to cancel their own jobs)
JESJOBS Class - ALTER access to SUBMIT.*.*.&RACUID (Allows users to submit their own jobs)
The ISSM may allow other classes to be included after evaluation with the system programmer.
Note: Be careful when adding any resource requiring auditing to Global Access Checking. RACF performs no logging other than that requested by the SETROPTS LOGOPTIONS command. There are other special consideration for global access checking found in the z/OS Security Server RACF Security Administrator's Guide.
If any other members are included for Global Access Checking, this is a finding.
If written approval by the ISSM is not provided, this is a finding.
M
4101