STIGQter STIGQter: STIG Summary: z/OS IBM CICS Transaction Server for ACF2 Security Technical Implementation Guide Version: 7 Release: 2 Benchmark Date: 01 Oct 2025:

ACF2/CICS parameter datasets are not protected in accordance with the proper security requirements.

DISA Rule

SV-224308r1141393_rule

Vulnerability Number

V-224308

Group Title

SRG-OS-000259

Rule Version

ZCICA011

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

The ISSO will ensure that WRITE and/or greater access to the ACF2/CICS parameter dataset is limited to systems programmers and security personnel.

Review the access authorizations for CICS system datasets.

WRITE and/or greater access to the ACF2/CICS parameter dataset, specified on the ACF2PARM DD statement, is restricted to systems programming personnel and security personnel.

Example:

$KEY(S3C)
$PREFIX(SYS3)
CICSTS.SYSIN UID(syspaudt) R(A) W(L) A(L) E(A)
CICSTS.SYSIN UID(secaaudt) R(A) W(L) A(L) E(A)
CICSTS.SYSIN UID(*) PREVENT

SET RULE
COMPILE 'ACF2.MVA.DSNRULES(S3C)' STORE

Check Contents

Refer to the following report produced by the ACF2 Data Collection:

- SENSITVE.RPT(CICSRPT).

Refer to the CICS Systems Programmer Worksheets filled out from previous vulnerability ZCIC0010.

WRITE and/or greater access to the ACF2/CICS parameter dataset, specified on the ACF2PARM DD statement, is restricted to systems programming personnel and security personnel. If this guidance is true, this is not a finding.

Vulnerability Number

V-224308

Documentable

False

Rule Version

ZCICA011

Severity Override Guidance

Refer to the following report produced by the ACF2 Data Collection:

- SENSITVE.RPT(CICSRPT).

Refer to the CICS Systems Programmer Worksheets filled out from previous vulnerability ZCIC0010.

WRITE and/or greater access to the ACF2/CICS parameter dataset, specified on the ACF2PARM DD statement, is restricted to systems programming personnel and security personnel. If this guidance is true, this is not a finding.

Check Content Reference

M

Target Key

4122