SV-224252r1141588_rule
V-224252
SRG-OS-000018
ZMVZA020
CAT II
10
The ISSO will work with the systems programmer to verify that the following are properly specified in the Access Control Program (ACP).
(Note: The resource type, resources, and/or resource prefixes identified below are examples of a possible installation. The actual resource type, resources, and/or prefixes are determined when the product is installed on a system through the product's installation guide and can be site specific.)
Use BMC MAINVIEW Resources table in the z/OS STIG Addendum. This table lists the resources, access requirements, and logging requirement for BMC MAINVIEW. Ensure the guidelines for the resource type, resources, and/or generic equivalent specified in the z/OS STIG Addendum are followed.
The ACF2 resources as designated in the above table are defined with a default access of PREVENT.
The ACF2 resource access authorizations restrict access to the appropriate personnel as designated in the above table.
The following commands are provided as a sample for implementing resource controls:
$KEY(BBM) TYPE(BMV)
ssid.CN UID(autoaudt) ALLOW
ssid.CN UID(dasdaudt) ALLOW
ssid.CN UID(mqsaaudt) ALLOW
ssid.CN UID(Mainview STCs) ALLOW
ssid.CN UID(mvzread) ALLOW
ssid.CN UID(mvzupdt) ALLOW
ssid.CN UID(pcspaudt) ALLOW
ssid.CN UID(syspaudt) ALLOW
- UID(*) PREVENT
Refer to the following report produced by the ACF2 Data Collection and dataset and Resource Data Collection:
- SENSITVE.RPT(ZMVZ0020).
- ACF2CMDS.RPT(RESOURCE) - Alternate report.
Automated Analysis
Refer to the following report produced by the dataset and Resource Data Collection:
- PDI(ZMVZ0020).
Verify that the accesses to resources and/or generic equivalent are properly restricted according to the requirements specified in BMC MAINVIEW Resources table in the z/OS STIG Addendum. If the following guidance is true, this is not a finding.
The ACF2 resources are defined with a default access of PREVENT.
The ACF2 resource access authorizations restrict access to the appropriate personnel.
V-224252
False
ZMVZA020
Refer to the following report produced by the ACF2 Data Collection and dataset and Resource Data Collection:
- SENSITVE.RPT(ZMVZ0020).
- ACF2CMDS.RPT(RESOURCE) - Alternate report.
Automated Analysis
Refer to the following report produced by the dataset and Resource Data Collection:
- PDI(ZMVZ0020).
Verify that the accesses to resources and/or generic equivalent are properly restricted according to the requirements specified in BMC MAINVIEW Resources table in the z/OS STIG Addendum. If the following guidance is true, this is not a finding.
The ACF2 resources are defined with a default access of PREVENT.
The ACF2 resource access authorizations restrict access to the appropriate personnel.
M
4109