STIGQter STIGQter: STIG Summary: z/OS Compuware Abend-AID for ACF2 Security Technical Implementation Guide Version: 7 Release: 2 Benchmark Date: 01 Oct 2025:

Compuware Abend-AID user datasets must be properly protected.

DISA Rule

SV-224292r1141335_rule

Vulnerability Number

V-224292

Group Title

SRG-OS-000080

Rule Version

ZAIDA002

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Ensure that WRITE and/or greater access to Compuware Abend-AID user datasets is limited to systems programmers and Compuware Abend-AID STC(s) and/or batch user(s) only.

Ensure that WRITE access to Compuware Abend-AID user datasets is limited to application development programmers and Application Production Support Team members. READ access can be given to auditors.

(Note: The datasets and/or dataset prefixes identified below are examples of a possible installation. The actual datasets and/or prefixes are determined when the product is installed on a system through the product's installation guide and can be site specific.)

Datasets to be protected will be:
Region dump datasets
Report databases
Source listing files/source listing shared directories

The following commands are provided as a sample for implementing dataset controls:

$KEY(S3A)
$PREFIX(SYS3)
ABENDAID.SHARED-.- UID(appdaudt) R(A) W(A)
ABENDAID.SHARED-.- UID(appsaudt) R(A) W(A)
ABENDAID.SHARED-.- UID(AbendAID STCs) R(A) W(A) A(A) E(A)
ABENDAID.SHARED-.- UID(syspaudt) R(A) W(A) A(A) E(A)

ABENDAID.SHARED-.- UID(tstcaudt) R(A) W(A) A(A) E(A)
ABENDAID.SHARED-.- UID(audtaudt) R(A)
ABENDAID.REPORTDB-.- UID(appdaudt) R(A) W(A)
ABENDAID.REPORTDB-.- UID(appsaudt) R(A) W(A)
ABENDAID.REPORTDB-.- UID(AbendAID STCs) R(A) W(A) A(A) E(A)
ABENDAID.REPORTED-.- UID(syspaudt) R(A) W(A) A(A) E(A)
ABENDAID.REPORTED-.- UID(tstcaudt) R(A) W(A) A(A) E(A)
ABENDAID.REPORTDB-.- UID(audtaudt) R(A)

SET RULE
COMPILE 'ACF2.MVA.DSNRULES(S3A)' STORE

Check Contents

Refer to the following report produced by the dataset and Resource Data Collection:

- SENSITVE.RPT(AIDUSER).

Automated Analysis
Refer to the following report produced by the dataset and Resource Data Collection:

- PDI(ZAID0002).

Verify that the accesses to the following Compuware Abend-AID user datasets are properly restricted. If the following guidance is true, this is not a finding.

Region dump datasets
Report databases
Source listing files/source listing shared directories

The ACF2 dataset rules for the listed datasets restrict READ access to auditors.

The ACF2 dataset rules for the listed datasets restrict WRITE and/or greater access to systems programming personnel.

The ACF2 dataset rules for the listed datasets restrict WRITE and/or greater access to the Compuware Abend-AID's STC(s) and/or batch user(s).

The ACF2 dataset rules for the listed datasets restrict WRITE access to application development programmers and Application Production Support Team members.

Vulnerability Number

V-224292

Documentable

False

Rule Version

ZAIDA002

Severity Override Guidance

Refer to the following report produced by the dataset and Resource Data Collection:

- SENSITVE.RPT(AIDUSER).

Automated Analysis
Refer to the following report produced by the dataset and Resource Data Collection:

- PDI(ZAID0002).

Verify that the accesses to the following Compuware Abend-AID user datasets are properly restricted. If the following guidance is true, this is not a finding.

Region dump datasets
Report databases
Source listing files/source listing shared directories

The ACF2 dataset rules for the listed datasets restrict READ access to auditors.

The ACF2 dataset rules for the listed datasets restrict WRITE and/or greater access to systems programming personnel.

The ACF2 dataset rules for the listed datasets restrict WRITE and/or greater access to the Compuware Abend-AID's STC(s) and/or batch user(s).

The ACF2 dataset rules for the listed datasets restrict WRITE access to application development programmers and Application Production Support Team members.

Check Content Reference

M

Target Key

4118