SV-224338r1141629_rule
V-224338
SRG-OS-000018
ZROSA020
CAT II
10
The ISSO will work with the systems programmer to verify that the following are properly specified in the Access Control Program (ACP).
(Note: The resource type, resources, and/or resource prefixes identified below are examples of a possible installation. The actual resource type, resources, and/or resource prefixes are determined when the product is installed on a system through the product's installation guide and can be site specific.)
Ensure that all ROSCOE resources and/or generic equivalent are properly protected according to the requirements specified in CA ROSCOE Resources table in the z/OS STIG Addendum.
Use CA ROSCOE Resources table in the z/OS STIG Addendum. This table lists the resources, access requirements, and logging requirements for ROSCOE ensure the following guidelines are followed:
The ACF2 resources are defined with a default access of PREVENT.
The ACF2 resource access authorizations restrict access to the appropriate personnel.
The ACF2 resource logging is correctly specified.
The following commands are provided as a sample for implementing resource controls:
$KEY(rosid) TYPE(ROS)
ROSCMD.ETSO UID(*) SEVICE(READ)
ROSCMD.MONITOR.- UID(syspaudt) ALLOW
ROSCMD.MONITOR.AMS UID(syspaudt) ALLOW
ROSCMD.MONITOR.AMS UID(*) SEVICE(READ)
ROSCMD.- UID(syspaudt) ALLOW
- UID(*) PREVENT
Refer to the following report produced by the ACF2 Data Collection and dataset and Resource Data Collection:
- SENSITVE.RPT(ZROS0020).
- ACF2CMDS.RPT(RESOURCE) - Alternate report.
Automated Analysis
Refer to the following report produced by the dataset and Resource Data Collection:
- PDI(ZROS0020).
Verify all ROSCOE resources and/or generic equivalent are properly protected according to the requirements specified in the CA ROSCOE Resources table in the z/OS STIG Addendum.
Note: Wherever an access or user group is missing, use the Site Security Plan to determine access and/or user group.
If the following guidance is true, this is not a finding.
The ACF2 resources are defined with a default access of PREVENT.
The ACF2 resource access authorizations restrict access to the appropriate personnel.
The ACF2 resource logging is correctly specified.
V-224338
False
ZROSA020
Refer to the following report produced by the ACF2 Data Collection and dataset and Resource Data Collection:
- SENSITVE.RPT(ZROS0020).
- ACF2CMDS.RPT(RESOURCE) - Alternate report.
Automated Analysis
Refer to the following report produced by the dataset and Resource Data Collection:
- PDI(ZROS0020).
Verify all ROSCOE resources and/or generic equivalent are properly protected according to the requirements specified in the CA ROSCOE Resources table in the z/OS STIG Addendum.
Note: Wherever an access or user group is missing, use the Site Security Plan to determine access and/or user group.
If the following guidance is true, this is not a finding.
The ACF2 resources are defined with a default access of PREVENT.
The ACF2 resource access authorizations restrict access to the appropriate personnel.
The ACF2 resource logging is correctly specified.
M
4128