STIGQter STIGQter: STIG Summary: IBM z/OS TSS Security Technical Implementation Guide Version: 8 Release: 2 Benchmark Date: 23 Apr 2021:

CA-TSS AUTH Control Option values specified must be set to (OVERRIDE,ALLOVER) or (MERGE,ALLOVER).

DISA Rule

SV-223922r561402_rule

Vulnerability Number

V-223922

Group Title

SRG-OS-000080-GPOS-00048

Rule Version

TSS0-ES-000490

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the AUTH control option is set to (OVERRIDE, ALLOVER) or (MERGE, ALLOVER). With (OVERRIDE, ALLOVER), TSS separately searches first the user, then profiles, and then the ALL record for its access authorization. With (MERGE, ALLOVER), TSS merges and searches the user and all profiles, and then the ALL record for its access authorization. Evaluate the impact associated with implementation of the control option. Develop a plan of action to implement the control option setting to AUTH(OVERRIDE, ALLOVER) or AUTH(MERGE, ALLOVER) and proceed with the change.

Check Contents

TSS MODIFY STATUS

If the AUTH Control Option values are not set to AUTH(OVERRIDE, ALLOVER) or AUTH(MERGE, ALLOVER), this is a finding.

Vulnerability Number

V-223922

Documentable

False

Rule Version

TSS0-ES-000490

Severity Override Guidance

TSS MODIFY STATUS

If the AUTH Control Option values are not set to AUTH(OVERRIDE, ALLOVER) or AUTH(MERGE, ALLOVER), this is a finding.

Check Content Reference

M

Target Key

4102

Comments