STIGQter STIGQter: STIG Summary: IBM z/OS TSS Security Technical Implementation Guide Version: 8 Release: 2 Benchmark Date: 23 Apr 2021:

Interactive ACIDs defined to CA-TSS must have the required fields completed.

DISA Rule

SV-223948r561402_rule

Vulnerability Number

V-223948

Group Title

SRG-OS-000104-GPOS-00051

Rule Version

TSS0-ES-000750

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Review all interactive ACID definitions to ensure required information is provided. Evaluate the impact of correcting the deficiency. Develop a plan of action and implement the changes as required according to the following:

FIELD DESCRIPTION VALUE
FACILITY Validated facilities to use BATCH, TSO, NCPASS, or other interactive Facility
PASSWORD logon password must have a value
INSTDATA Installation data optional
PROFILE Profile(s) optional
TSOLPROC Default TSO logon PROC optional for TSO users
TSOLACCT Default TSO logon account may be required
for a fee for service.

Check Contents

From the ISPF Command Shell enter:
TSS LIST (ACIDs) DATA (BASIC,TSO,CICS)

If all the fields and information listed below, are not present for all interactive users this is a finding.

FIELD DESCRIPTION VALUE
FACILITY Validated facilities to use BATCH, TSO, NCPASS, or other interactive Facility
PASSWORD logon password must have a value
INSTDATA Installation data optional
PROFILE Profile(s) optional
TSOLPROC Default TSO logon PROC optional for TSO users
TSOLACCT Default TSO logon account may be required for a fee for service.

Vulnerability Number

V-223948

Documentable

False

Rule Version

TSS0-ES-000750

Severity Override Guidance

From the ISPF Command Shell enter:
TSS LIST (ACIDs) DATA (BASIC,TSO,CICS)

If all the fields and information listed below, are not present for all interactive users this is a finding.

FIELD DESCRIPTION VALUE
FACILITY Validated facilities to use BATCH, TSO, NCPASS, or other interactive Facility
PASSWORD logon password must have a value
INSTDATA Installation data optional
PROFILE Profile(s) optional
TSOLPROC Default TSO logon PROC optional for TSO users
TSOLACCT Default TSO logon account may be required for a fee for service.

Check Content Reference

M

Target Key

4102

Comments