SV-224495r1144706_rule
V-224495
SRG-OS-000104
ZCIC0040
CAT II
10
Review all CICS region, default, and end-user userids to ensure they are defined and controlled as required.
Ensure that the following is defined for each CICS region:
A unique userid is defined.
Use the RACF Adduser command to accomplish this. A sample command is provided here:
AU <cicsregionid> NAME('STC, CICS Region') DFLTGRP(STC) OWNER(STC)
Defined to the STARTED resource class.
Use the RACF RDEFINE command. A sample is provided here:
RDEF STARTED <cicsprocname>.** UACC(NONE) OWNER(ADMIN) DATA('USED TO MAP <cicsprocname> TO A VALID RACF USERID') STDATA(USER(=MEMBER) GROUP(STC) TRACE(YES))
Refer to the following report produced by the z/OS Data Collection:
- EXAM.RPT(CICSPROC).
Refer to the following reports produced by the RACF Data Collection:
- RACFCMDS.RPT(LISTUSER).
- DSMON.RPT(RACCDT).
Refer to the CICS Systems Programmer Worksheets filled out from previous vulnerability ZCIC0010.
If the following is defined for each CICS region, this is not a finding.
A unique userid is defined.
Defined to the STARTED resource class.
V-224495
False
ZCIC0040
Refer to the following report produced by the z/OS Data Collection:
- EXAM.RPT(CICSPROC).
Refer to the following reports produced by the RACF Data Collection:
- RACFCMDS.RPT(LISTUSER).
- DSMON.RPT(RACCDT).
Refer to the CICS Systems Programmer Worksheets filled out from previous vulnerability ZCIC0010.
If the following is defined for each CICS region, this is not a finding.
A unique userid is defined.
Defined to the STARTED resource class.
M
4154