STIGQter STIGQter: STIG Summary: IBM z/OS TSS Security Technical Implementation Guide Version: 8 Release: 2 Benchmark Date: 23 Apr 2021:

CA-TSS ACIDs must not have access to FAC(*ALL*).

DISA Rule

SV-223926r561402_rule

Vulnerability Number

V-223926

Group Title

SRG-OS-000080-GPOS-00048

Rule Version

TSS0-ES-000520

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

The ISSO will ensure that blanket access to all facilities; FACILITY(ALL), is never granted.

Review all access to FACILITY(*ALL*). Evaluate the impact of correcting the deficiency. Develop a plan of action and remove access to FAC(*ALL*).

Example:
TSS REM(acid) FAC(ALL)

Check Contents

From the ISPF Command Shell enter:
TSS LIST(ACIDS) DATA(BASIC)

If any ACID(s) is (are) assigned FACILITY(*ALL*), this is a finding.

Vulnerability Number

V-223926

Documentable

False

Rule Version

TSS0-ES-000520

Severity Override Guidance

From the ISPF Command Shell enter:
TSS LIST(ACIDS) DATA(BASIC)

If any ACID(s) is (are) assigned FACILITY(*ALL*), this is a finding.

Check Content Reference

M

Target Key

4102

Comments