STIGQter STIGQter: STIG Summary: z/OS CA 1 Tape Management for ACF2 Security Technical Implementation Guide Version: 7 Release: 2 Benchmark Date: 01 Oct 2025:

CA 1 Tape Management STC datasets must be properly protected.

DISA Rule

SV-224259r1141353_rule

Vulnerability Number

V-224259

Group Title

SRG-OS-000259

Rule Version

ZCA1A001

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Ensure that WRITE and/or greater access to CA1 Tape management STC datasets is limited to systems programmers and/or CA1 Tape management STC(s) and/or batch user(s) only.

(Note: The datasets and/or dataset prefixes identified below are examples of a possible installation. The actual datasets and/or prefixes are determined when the product is installed on a system through the product's installation guide and can be site specific.)

Datasets to be protected will be:
CA1.TMS* (Datasets that are altered by the product's STCs can be more specific.)

The following commands are provided as a sample for implementing dataset controls:

$KEY(SYS3)
CA1.TMS*.**- UID(<syspaudt>) R(A) W(A) A(A) E(A)
CA1.TMS*.**- UID(<Tape Management STCs and/or batch users >) R(A) W(A) A(A) E(A)
CA1.TMS*.**- UID(<audtaudt>) R(A) E(A)

Check Contents

Refer to the following report produced by the ACF2 Data Collection and dataset and Resource Data Collection:

- SENSITVE.RPT(CA1STC).

Automated Analysis
Refer to the following report produced by the dataset and Resource Data Collection:

- PDI(ZCA10001).

Verify that the accesses to CA1 Tape Management Started Tasks (STCs) datasets are properly restricted. If the following guidance is true, this is not a finding.

The ACF2 dataset access authorizations restrict READ access to auditors.

The ACF2 dataset access authorizations restrict WRITE and/or greater access to systems programming personnel.

The ACF2 dataset access authorizations restrict WRITE and/or greater access to CA1 Tape Management STCs and/or batch users.

Vulnerability Number

V-224259

Documentable

False

Rule Version

ZCA1A001

Severity Override Guidance

Refer to the following report produced by the ACF2 Data Collection and dataset and Resource Data Collection:

- SENSITVE.RPT(CA1STC).

Automated Analysis
Refer to the following report produced by the dataset and Resource Data Collection:

- PDI(ZCA10001).

Verify that the accesses to CA1 Tape Management Started Tasks (STCs) datasets are properly restricted. If the following guidance is true, this is not a finding.

The ACF2 dataset access authorizations restrict READ access to auditors.

The ACF2 dataset access authorizations restrict WRITE and/or greater access to systems programming personnel.

The ACF2 dataset access authorizations restrict WRITE and/or greater access to CA1 Tape Management STCs and/or batch users.

Check Content Reference

M

Target Key

4110