STIGQter STIGQter: STIG Summary: IBM z/OS RACF Security Technical Implementation Guide Version: 8 Release: 3 Benchmark Date: 23 Apr 2021:

The IBM RACF ERASE ALL SETROPTS value must be set to ERASE(ALL) on all systems.

DISA Rule

SV-223731r604139_rule

Vulnerability Number

V-223731

Group Title

SRG-OS-000138-GPOS-00069

Rule Version

RACF-ES-000840

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the ERASE SETROPTS value to ERASE(ALL) this allows DASD datasets to be erased when deleted.

Evaluate the impact associated with implementation of the control option. Develop a plan of action to implement the control option as specified in the example below:

-Issue the RACF Command SETR LIST to show the status of RACF Controls including the status of the ERASE options.

-Take the appropriate actions to ensure that the SETR ERASE(ALL) has been issued to enable Erase On Scratch for all datasets.

Check Contents

From the ISPF Command Shell enter:
SETRopts List

For all systems, if the ERASE values are set as follows, this is not a finding.

ERASE-ON-SCRATCH IS ACTIVE, CURRENT OPTIONS:
ERASE-ON-SCRATCH FOR ALL DATA SETS IS IN EFFECT

Vulnerability Number

V-223731

Documentable

False

Rule Version

RACF-ES-000840

Severity Override Guidance

From the ISPF Command Shell enter:
SETRopts List

For all systems, if the ERASE values are set as follows, this is not a finding.

ERASE-ON-SCRATCH IS ACTIVE, CURRENT OPTIONS:
ERASE-ON-SCRATCH FOR ALL DATA SETS IS IN EFFECT

Check Content Reference

M

Target Key

4101

Comments