STIGQter STIGQter: STIG Summary: IBM z/OS TSS Security Technical Implementation Guide Version: 8 Release: 2 Benchmark Date: 23 Apr 2021:

CA-TSS must limit access to System page data sets (i.e., PLPA, COMMON, and LOCALx) to system programmers only.

DISA Rule

SV-223913r561402_rule

Vulnerability Number

V-223913

Group Title

SRG-OS-000080-GPOS-00048

Rule Version

TSS0-ES-000400

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the ESM data set rules for system page data sets (PLPA, COMMON, and LOCAL) to restrict access to only systems programming personnel.

Auditors may be allowed READ Access as approved by the ISSM.

Check Contents

Execute a dataset list of access for System page data sets (i.e., PLPA, COMMON, and LOCALx).

If ESM data set rules for system page data sets (PLPA, COMMON, and LOCAL) restrict access to only systems programming personnel, this is not a finding.

If ESM data set rules for system page data sets (PLPA, COMMON, and LOCAL) restrict auditors to READ only, this is not a finding.

Vulnerability Number

V-223913

Documentable

False

Rule Version

TSS0-ES-000400

Severity Override Guidance

Execute a dataset list of access for System page data sets (i.e., PLPA, COMMON, and LOCALx).

If ESM data set rules for system page data sets (PLPA, COMMON, and LOCAL) restrict access to only systems programming personnel, this is not a finding.

If ESM data set rules for system page data sets (PLPA, COMMON, and LOCAL) restrict auditors to READ only, this is not a finding.

Check Content Reference

M

Target Key

4102

Comments