STIGQter STIGQter: STIG Summary: z/OS IBM CICS Transaction Server for ACF2 Security Technical Implementation Guide Version: 7 Release: 2 Benchmark Date: 01 Oct 2025:

Sensitive CICS transactions are not protected in accordance with the proper security requirements.

DISA Rule

SV-224313r1141405_rule

Vulnerability Number

V-224313

Group Title

SRG-OS-000324

Rule Version

ZCICA025

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

The systems programmer and ISSO will ensure the ACF2/CICS parameter PROTLIST is not coded.

Browse the ACF2/CICS dataset allocated by the ACF2PARM DD statement in the JCL of each CICS procedure.

Make sure the PROTLIST parameter is not specified for all CICS regions.

Check Contents

Refer to the following report produced by the z/OS Data Collection:

- EXAM.RPT(CICSPROC).

Refer to the CICS Systems Programmer Worksheets filled out from previous vulnerability ZCIC0010.

Browse the ACF2/CICS dataset allocated by the ACF2PARM DD statement in the JCL of each CICS procedure.

If the PROTLIST parameter is not specified for all CICS regions, this is not a finding.

Vulnerability Number

V-224313

Documentable

False

Rule Version

ZCICA025

Severity Override Guidance

Refer to the following report produced by the z/OS Data Collection:

- EXAM.RPT(CICSPROC).

Refer to the CICS Systems Programmer Worksheets filled out from previous vulnerability ZCIC0010.

Browse the ACF2/CICS dataset allocated by the ACF2PARM DD statement in the JCL of each CICS procedure.

If the PROTLIST parameter is not specified for all CICS regions, this is not a finding.

Check Content Reference

M

Target Key

4122