STIGQter STIGQter: STIG Summary: z/OS Front End Processor for RACF Security Technical Implementation Guide Version: 7 Release: 2 Benchmark Date: 01 Oct 2025:

NCP (Net Work Control Program) Data set access authorization does not restricts UPDATE and/or ALLOCATE access to appropriate personnel.

DISA Rule

SV-224487r1144839_rule

Vulnerability Number

V-224487

Group Title

SRG-OS-000259

Rule Version

ZFEP0015

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Identify Names of the following data sets used for installation and in development/production environments:

- NCP system data sets
- NCP source definition data sets
- NCP load modules
- NCP host dump data sets
- NCP utility programs

Have the ISSO validate that they are properly protected by the ACP. And that only authorized personnel are permitted UPDATE and/or ALLOCATE access (e.g., z/OS systems programming personnel).

Check Contents

Refer to the following report produced by the Data Set and Resource Data Collection:

- SENSITVE.RPT(NCPRPT).

The ACP data set rules for NCP data sets restrict WRITE and/or greater access to authorized personnel (e.g., systems programming personnel), this is not a finding.

Vulnerability Number

V-224487

Documentable

False

Rule Version

ZFEP0015

Severity Override Guidance

Refer to the following report produced by the Data Set and Resource Data Collection:

- SENSITVE.RPT(NCPRPT).

The ACP data set rules for NCP data sets restrict WRITE and/or greater access to authorized personnel (e.g., systems programming personnel), this is not a finding.

Check Content Reference

M

Target Key

4152