STIGQter STIGQter: STIG Summary: z/OS IBM Health Checker for TSS Security Technical Implementation Guide Version: 7 Release: 1 Benchmark Date: 02 Jul 2025:

IBM Health Checker Started Task name will be properly identified and/or defined to the system Access Control Program (ACP).

DISA Rule

SV-224739r1116173_rule

Vulnerability Number

V-224739

Group Title

SRG-OS-000104

Rule Version

ZHCKT030

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

The ISSO working with the systems programmer will ensure the IBM Health Checker Started Task(s) is properly identified and/or defined to the System ACP.

If the product requires a Started Task, verify that it is properly defined to the System ACP with the proper attributes.

Most installation manuals will indicate how the Started Task is identified and any additional attributes that must be specified.

The following commands are provided as a sample for defining Started Task(s):

TSS CREATE(HZSPROD) TYPE(USER) -
NAME('STC, IBM Health Checker') DEPT(xxxx) -
FAC(STC,BATCH) PASS(xxxxxxxx,0) -
SOURCE(INTRDR) NOSUSPEND

Check Contents

Refer to the following report produced by the TSS Data Collection:

- TSSCMDS.RPT(@ACIDS)

Verify that the ACID(s) for the IBM Health Checker started task(s) is (are) properly defined. If the following attributes are defined, this is not a finding.

FACILITY(STC, BATCH)
PASSWORD(xxxxxxxx,0)
SOURCE(INTRDR)
NOSUSPEND

Vulnerability Number

V-224739

Documentable

False

Rule Version

ZHCKT030

Severity Override Guidance

Refer to the following report produced by the TSS Data Collection:

- TSSCMDS.RPT(@ACIDS)

Verify that the ACID(s) for the IBM Health Checker started task(s) is (are) properly defined. If the following attributes are defined, this is not a finding.

FACILITY(STC, BATCH)
PASSWORD(xxxxxxxx,0)
SOURCE(INTRDR)
NOSUSPEND

Check Content Reference

M

Target Key

4196