STIGQter STIGQter: STIG Summary: IBM z/OS TSS Security Technical Implementation Guide Version: 8 Release: 2 Benchmark Date: 23 Apr 2021:

Data set masking characters must be properly defined to the CA-TSS security database.

DISA Rule

SV-223924r561402_rule

Vulnerability Number

V-223924

Group Title

SRG-OS-000080-GPOS-00048

Rule Version

TSS0-ES-000505

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure all data set masking characters to be owned the MSCA.

Example TSS commands to protect masking characters:

TSS ADD(msca) DSN(*)
TSS ADD(msca) DSN(%)
TSS ADD(msca) DSN(+)

Check Contents

From the ISPF Command Shell enter:
TSS WHOOWNS data set(*)

If data set masking characters. (*, %, and +, **) are owned by the MSCA, this is not a finding.

Vulnerability Number

V-223924

Documentable

False

Rule Version

TSS0-ES-000505

Severity Override Guidance

From the ISPF Command Shell enter:
TSS WHOOWNS data set(*)

If data set masking characters. (*, %, and +, **) are owned by the MSCA, this is not a finding.

Check Content Reference

M

Target Key

4102

Comments