STIGQter STIGQter: STIG Summary: z/OS IBM CICS Transaction Server for RACF Security Technical Implementation Guide Version: 7 Release: 2 Benchmark Date: 01 Oct 2025:

CICS logonid(s) must have timeout limit set to 15 minutes.

DISA Rule

SV-224497r1144711_rule

Vulnerability Number

V-224497

Group Title

SRG-OS-000029

Rule Version

ZCIC0042

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Review all CICS region, default, and end-user userids to ensure they are defined and controlled as required.

Ensure that all userids with a CICS segment have the TIMEOUT parameter set to 15 minutes.

Examples: Use the RACF ALtUser command to assign the required value:

ALU <cics user> CICS(TIMEOUT(15))

Check Contents

Refer to the following report produced by the RACF Data Collection:

- RACFCMDS.RPT(LISTUSER.

Refer to the CICS Systems Programmer Worksheets filled out from previous vulnerability ZCIC0010.

Note: Any userid that does not have a TIMEOUT parameter specified will obtain its TIMEOUT parameter from the default value set in ZCIC0041. Any userid that specifies a TIMEOUT parameter must meet the requirements specified below.

Verify that all userids with a CICS segment have the TIMEOUT parameter set to 15 minutes, this is not a finding.

Note: If the timeout limit is greater than 15 minutes, and the system is processing unclassified information, review the following items. If any of these is true, this is not a finding.

If a session is not terminated, but instead is locked out after 15 minutes of inactivity, a process must be in place that requires user identification and authentication before the session is unlocked. Session lockout will be implemented through system controls or terminal screen protection.
A system's default time for terminal lockout or session termination may be lengthened to 30 minutes at the discretion of the ISSM. The ISSM will maintain the documentation for each system with a timeout adjusted beyond the 15-minute recommendation to explain the basis for this decision.
The ISSM may set selected userids to have a timeout of up to 60 minutes in order to complete critical reports or transactions without timing out. Each exception must meet the following criteria:

The timeout exception cannot exceed 60 minutes.
A letter of justification fully documenting the user requirement(s) must be submitted and approved by the site ISSM. In addition, this letter must identify an alternate means of access control for the terminal(s) involved (e.g., a room that is locked at all times, a room with a cipher lock to limit access, a password protected screen saver set to 30 minutes or less, etc.).

The requirement must be revalidated on an annual basis.

If the CICS timeout limit is not specified for 15 minutes of inactivity, and the previously mentioned exceptions do not apply, this is a finding.

Vulnerability Number

V-224497

Documentable

False

Rule Version

ZCIC0042

Severity Override Guidance

Refer to the following report produced by the RACF Data Collection:

- RACFCMDS.RPT(LISTUSER.

Refer to the CICS Systems Programmer Worksheets filled out from previous vulnerability ZCIC0010.

Note: Any userid that does not have a TIMEOUT parameter specified will obtain its TIMEOUT parameter from the default value set in ZCIC0041. Any userid that specifies a TIMEOUT parameter must meet the requirements specified below.

Verify that all userids with a CICS segment have the TIMEOUT parameter set to 15 minutes, this is not a finding.

Note: If the timeout limit is greater than 15 minutes, and the system is processing unclassified information, review the following items. If any of these is true, this is not a finding.

If a session is not terminated, but instead is locked out after 15 minutes of inactivity, a process must be in place that requires user identification and authentication before the session is unlocked. Session lockout will be implemented through system controls or terminal screen protection.
A system's default time for terminal lockout or session termination may be lengthened to 30 minutes at the discretion of the ISSM. The ISSM will maintain the documentation for each system with a timeout adjusted beyond the 15-minute recommendation to explain the basis for this decision.
The ISSM may set selected userids to have a timeout of up to 60 minutes in order to complete critical reports or transactions without timing out. Each exception must meet the following criteria:

The timeout exception cannot exceed 60 minutes.
A letter of justification fully documenting the user requirement(s) must be submitted and approved by the site ISSM. In addition, this letter must identify an alternate means of access control for the terminal(s) involved (e.g., a room that is locked at all times, a room with a cipher lock to limit access, a password protected screen saver set to 30 minutes or less, etc.).

The requirement must be revalidated on an annual basis.

If the CICS timeout limit is not specified for 15 minutes of inactivity, and the previously mentioned exceptions do not apply, this is a finding.

Check Content Reference

M

Target Key

4154