SV-224115r1141453_rule
V-224115
SRG-OS-000259
ZCTMA001
CAT II
10
The ISSO will ensure that WRITE and/or greater access to BMC CONTROL-M STC datasets is limited to systems programmers only. UPDATE access can be given to scheduled batch jobs, operations, production control and scheduling personnel, BMC STCs, and/or batch users. READ access can be given to auditors and/or BMC users.
The installing systems programmer will identify and document the product datasets, categorize them according to who will have WRITE and/or greater access, and if required, ensure that all WRITE and/or greater access is logged. The installing systems programmer will identify if any additional groups have WRITE and/or greater access for specific datasets, and once documented will work with the ISSO to ensure they are properly restricted to the ACP (Access Control Program) active on the system.
(Note: The datasets and/or dataset prefixes identified below are examples of a possible installation. The actual datasets and/or prefixes are determined when the product is installed on a system through the product's installation guide and can be site specific.)
Datasets to be protected will be:
SYS3.IOA.*.CTMO
The following commands are provided as a sample for implementing dataset controls:
$KEY(SYS3)
IOA.-.CTMO.- UID(<syspaudt>) R(A) W(A) A(A) E(A)
IOA.-.CTMO.- UID(<tstcaudt>) R(A) W(A) A(A) E(A)
IOA.-.CTMO.- UID(CONTDAY) R(A) W(A) E(A)
IOA.-.CTMO.- UID(CONTROLM) R(A) W(A) E(A)
IOA.-.CTMO.- UID(<autoaudt>) R(A) W(A) E(A)
IOA.-.CTMO.- UID(<operaudt>) R(A) W(A) E(A)
IOA.-.CTMO.- UID(<pcspaudt>) R(A) W(A) E(A)
IOA.-.CTMO.- UID(<audtaudt>) R(A) E(A)
IOA.-.CTMO.- UID(<bmcuser>) R(A) E(A)
Refer to the following report produced by the dataset and Resource Data Collection:
- SENSITVE.RPT(CTMSTC).
Automated Analysis
Refer to the following report produced by the dataset and Resource Data Collection:
- PDI(ZCTM0001).
Verify that the accesses to the BMC CONTROL-M STC datasets are properly restricted. If the following guidance is true, this is not a finding.
The ACF2 dataset access authorizations restrict READ access to auditors and BMC users.
The ACF2 dataset access authorizations restrict WRITE and/or greater access to systems programming personnel.
The ACF2 dataset access authorizations restrict UPDATE access to the BMC STCs and/or batch users.
The ACF2 dataset access authorizations restrict UPDATE access to scheduled batch jobs, operations, and production control and scheduling personnel.
V-224115
False
ZCTMA001
Refer to the following report produced by the dataset and Resource Data Collection:
- SENSITVE.RPT(CTMSTC).
Automated Analysis
Refer to the following report produced by the dataset and Resource Data Collection:
- PDI(ZCTM0001).
Verify that the accesses to the BMC CONTROL-M STC datasets are properly restricted. If the following guidance is true, this is not a finding.
The ACF2 dataset access authorizations restrict READ access to auditors and BMC users.
The ACF2 dataset access authorizations restrict WRITE and/or greater access to systems programming personnel.
The ACF2 dataset access authorizations restrict UPDATE access to the BMC STCs and/or batch users.
The ACF2 dataset access authorizations restrict UPDATE access to scheduled batch jobs, operations, and production control and scheduling personnel.
M
4104