STIGQter STIGQter: STIG Summary: IBM z/OS RACF Security Technical Implementation Guide Version: 8 Release: 3 Benchmark Date: 23 Apr 2021:

The IBM RACF System REXX IRRPWREX security data set must be properly protected.

DISA Rule

SV-223684r604139_rule

Vulnerability Number

V-223684

Group Title

SRG-OS-000080-GPOS-00048

Rule Version

RACF-ES-000360

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure read access to be restricted to security administrators, systems programmers, and auditors.

Establish a procedure documented with the ISSM that defines a change management process to provide mechanism for granting Update access to security administrators on an exception basis. The process should contain procedures to revoke access when documented update is completed.

Configure all failures and successes data set access authorities for RACF data set that contains the Password exit to be logged.

Examples:
ad 'sys3.racf.rexxlib.**' quack(none) owner(sys3) -
audit(all(read))
Permit 'sys3.racf.rexxlib.**' id(<syspsmpl> <secasmpl> <smplsmpl> AXRUSER) acc(r)
Permit 'sys3.racf.rexxlib.**' id(<secasmpl>) acc(u)

Check Contents

Refer to the zOS system REXXLIB concatenation found in SYS1. PARMLIB (AXR) for the data set that contains the REXX for Password exit named IRRPWREX and the defined AXRUSER.

If the following guidance is true, this is not a finding.

-RACF data set access authorizations restrict READ to AXRUSER, z/OS systems programming personnel, security personnel, and auditors.
-RACF data set access authorizations restrict UPDATE to security personnel using a documented change management procedure to provide a mechanism for access and revoking of access after use.
-All (i.e., failures and successes) data set access authorities (i.e., READ, UPDATE, and CONTROL) is logged.
-RACF data set access authorizations specify UACC(NONE) and NOWARNING.

Vulnerability Number

V-223684

Documentable

False

Rule Version

RACF-ES-000360

Severity Override Guidance

Refer to the zOS system REXXLIB concatenation found in SYS1. PARMLIB (AXR) for the data set that contains the REXX for Password exit named IRRPWREX and the defined AXRUSER.

If the following guidance is true, this is not a finding.

-RACF data set access authorizations restrict READ to AXRUSER, z/OS systems programming personnel, security personnel, and auditors.
-RACF data set access authorizations restrict UPDATE to security personnel using a documented change management procedure to provide a mechanism for access and revoking of access after use.
-All (i.e., failures and successes) data set access authorities (i.e., READ, UPDATE, and CONTROL) is logged.
-RACF data set access authorizations specify UACC(NONE) and NOWARNING.

Check Content Reference

M

Target Key

4101

Comments