STIGQter STIGQter: STIG Summary: IBM z/OS RACF Security Technical Implementation Guide Version: 8 Release: 3 Benchmark Date: 23 Apr 2021:

IBM RACF must limit access to System page data sets (i.e., PLPA, COMMON, and LOCALx) to system programmers.

DISA Rule

SV-223688r604139_rule

Vulnerability Number

V-223688

Group Title

SRG-OS-000080-GPOS-00048

Rule Version

RACF-ES-000400

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the ESM data set rules for system page data sets (PLPA, COMMON, and LOCAL) to restrict access to only systems programming personnel.
Auditors may be allowed READ Access as approved by the ISSM.

Check Contents

Execute a dataset list of access for System page data sets (i.e., PLPA, COMMON, and LOCALx).

If ESM data set rules for system page data sets (PLPA, COMMON, and LOCAL) restrict access to only systems programming personnel, this is not a finding.

If ESM data set rules for system page data sets (PLPA, COMMON, and LOCAL) restrict auditors to READ only, this is not a finding.

Vulnerability Number

V-223688

Documentable

False

Rule Version

RACF-ES-000400

Severity Override Guidance

Execute a dataset list of access for System page data sets (i.e., PLPA, COMMON, and LOCALx).

If ESM data set rules for system page data sets (PLPA, COMMON, and LOCAL) restrict access to only systems programming personnel, this is not a finding.

If ESM data set rules for system page data sets (PLPA, COMMON, and LOCAL) restrict auditors to READ only, this is not a finding.

Check Content Reference

M

Target Key

4101

Comments