STIGQter STIGQter: STIG Summary: z/OS BMC CONTROL-O for ACF2 Security Technical Implementation Guide Version: 7 Release: 2 Benchmark Date: 01 Oct 2025:

BMC CONTROL-O installation datasets will be properly protected.

DISA Rule

SV-224126r1144182_rule

Vulnerability Number

V-224126

Group Title

SRG-OS-000080

Rule Version

ZCTOA000

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

The ISSO will ensure that WRITE and/or greater access to BMC CONTROL-O installation datasets is limited to systems programmers only, and all WRITE and/or greater access is logged. READ access can be given to auditors, BMC users, and BMC STCs and/or batch users. All failures and successful WRITE and/or greater accesses are logged.

The installing systems programmer will identify and document the product datasets, categorize them according to who will have WRITE and/or greater access, and if required, ensure that all WRITE and/or greater access is logged. The installing systems programmer will identify if any additional groups have WRITE and/or greater access for specific datasets, and once documented, will work with the ISSO to ensure they are properly restricted to the Access Control Program (ACP) active on the system.

(Note: The datasets and/or dataset prefixes identified below are examples of a possible installation. The actual datasets and/or prefixes are determined when the product is installed on a system through the product's installation guide and can be site specific.)

Datasets to be protected will be:
SYS2.IOA.*.CTOI

The following commands are provided as a sample for implementing dataset controls:

$KEY(SYS2)
IOA.-.CTOI.- UID(<syspaudt>) R(A) W(L) A(L) E(A)
IOA.-.CTOI.- UID(<audtaudt>) R(A) E(A)
IOA.-.CTOI.- UID(<bmcuser>) R(A) E(A)
IOA.-.CTOI.- UID(CONTROLO) R(A) E(A)

Check Contents

Refer to the following report produced by the dataset and Resource Data Collection:

- SENSITVE.RPT(CTORPT).

Automated Analysis
Refer to the following report produced by the dataset and Resource Data Collection:

- PDI(ZCTO0000).

Verify that the accesses to the BMC CONTROL-O installation datasets are properly restricted. If the following guidance is true, this is not a finding.

The ACF2 dataset rules for the datasets restrict READ access to auditors, BMC users, and BMC STCs and/or batch users.

The ACF2 dataset rules for the datasets restrict WRITE and/or greater access to systems programming personnel.

The ACF2 dataset rules for the datasets specify that all (i.e., failures and successes) WRITE and/or greater access is logged.

Vulnerability Number

V-224126

Documentable

False

Rule Version

ZCTOA000

Severity Override Guidance

Refer to the following report produced by the dataset and Resource Data Collection:

- SENSITVE.RPT(CTORPT).

Automated Analysis
Refer to the following report produced by the dataset and Resource Data Collection:

- PDI(ZCTO0000).

Verify that the accesses to the BMC CONTROL-O installation datasets are properly restricted. If the following guidance is true, this is not a finding.

The ACF2 dataset rules for the datasets restrict READ access to auditors, BMC users, and BMC STCs and/or batch users.

The ACF2 dataset rules for the datasets restrict WRITE and/or greater access to systems programming personnel.

The ACF2 dataset rules for the datasets specify that all (i.e., failures and successes) WRITE and/or greater access is logged.

Check Content Reference

M

Target Key

4106