STIGQter STIGQter: STIG Summary: z/OS BMC CONTROL-M for ACF2 Security Technical Implementation Guide Version: 7 Release: 2 Benchmark Date: 01 Oct 2025:

BMC CONTROL-M security exits are not installed or configured properly.

DISA Rule

SV-224113r1041243_rule

Vulnerability Number

V-224113

Group Title

SRG-OS-000018

Rule Version

ZCTM0060

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

The systems programmer responsible for the BMC CONTROL-M will review the BMC CONTROL-M operating environment. Ensure that the following security exit(s) is (are) installed properly. Determine if the site has modified the following security exit(s):

CTMSE01
CTMSE02
CTMSE08

Ensure that the security exit(s) has (have) not been modified.

If the security exit(s) has (have) been modified, ensure the security exit(s) has (have) been checked as to not violate any security integrity within the system and approval documentation is on file.

Check Contents

Interview the systems programmer responsible for the BMC CONTROL-M. Determine if the site has modified the following security exit(s):

CTMSE01
CTMSE02
CTMSE08

Ensure the above security exit(s) has (have) not been modified.

If the above security exit(s) has (have) been modified, ensure that the security exit(s) has (have) been approved by the site systems programmer and the approval is on file for examination.

Vulnerability Number

V-224113

Documentable

False

Rule Version

ZCTM0060

Severity Override Guidance

Interview the systems programmer responsible for the BMC CONTROL-M. Determine if the site has modified the following security exit(s):

CTMSE01
CTMSE02
CTMSE08

Ensure the above security exit(s) has (have) not been modified.

If the above security exit(s) has (have) been modified, ensure that the security exit(s) has (have) been approved by the site systems programmer and the approval is on file for examination.

Check Content Reference

M

Target Key

4104