STIGQter STIGQter: STIG Summary: z/OS BMC CONTROL-O for ACF2 Security Technical Implementation Guide Version: 7 Release: 2 Benchmark Date: 01 Oct 2025:

BMC CONTROL-O configuration/parameter values are not specified properly.

DISA Rule

SV-224124r1141473_rule

Vulnerability Number

V-224124

Group Title

SRG-OS-000080

Rule Version

ZCTO0041

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

The BMC CONTROL-O systems programmer will verify that any configuration/parameters that are required to control the security of the product are properly configured and syntactically correct. Set the standard values for the BMC CONTROL-O security parameters for the specific Access Control Program (ACP) environment along with additional IOA security parameters with standard values as documented below.

Keyword Value
RUNTDFT OWNER
RUNTCACH 100
AUTOMLOG V

Check Contents

Refer to the following applicable reports produced by the z/OS Data Collection:

- IOA.RPT(CTOPARM).

Automated Analysis
Refer to the following report produced by the z/OS Data Collection:

- PDI(ZCTO0041).

The following keywords will have the specified values in the BMC CONTROL-O security parameter member. This is not a finding.

Keyword Value
RUNTDFT OWNER
RUNTCACH 100
AUTOMLOG V

Vulnerability Number

V-224124

Documentable

False

Rule Version

ZCTO0041

Severity Override Guidance

Refer to the following applicable reports produced by the z/OS Data Collection:

- IOA.RPT(CTOPARM).

Automated Analysis
Refer to the following report produced by the z/OS Data Collection:

- PDI(ZCTO0041).

The following keywords will have the specified values in the BMC CONTROL-O security parameter member. This is not a finding.

Keyword Value
RUNTDFT OWNER
RUNTCACH 100
AUTOMLOG V

Check Content Reference

M

Target Key

4106