STIGQter STIGQter: STIG Summary: z/OS Front End Processor for ACF2 Security Technical Implementation Guide Version: 7 Release: 2 Benchmark Date: 01 Oct 2025:

NCP (Net Work Control Program) dataset access authorization does not restricts UPDATE and/or ALLOCATE access to appropriate personnel.

DISA Rule

SV-230187r1141511_rule

Vulnerability Number

V-230187

Group Title

SRG-OS-000259

Rule Version

ZFEP0015

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Identify Names of the following datasets used for installation and in development/production environments:

- NCP system datasets.
- NCP source definition datasets.
- NCP load modules.
- NCP host dump datasets.
- NCP utility programs.

Have the ISSO validate that they are properly protected by the ACP and that only authorized personnel are permitted WRITE and/or greater access (e.g., z/OS systems programming personnel).

Check Contents

Refer to the following report produced by the dataset and Resource Data Collection:

- SENSITVE.RPT(NCPRPT).

The ACP dataset rules for NCP datasets allow inappropriate access. If the following guidance is true, this is not a finding.

The ACP dataset rules for NCP datasets restrict WRITE and/or greater access to authorized personnel (e.g., systems programming personnel).

Vulnerability Number

V-230187

Documentable

False

Rule Version

ZFEP0015

Severity Override Guidance

Refer to the following report produced by the dataset and Resource Data Collection:

- SENSITVE.RPT(NCPRPT).

The ACP dataset rules for NCP datasets allow inappropriate access. If the following guidance is true, this is not a finding.

The ACP dataset rules for NCP datasets restrict WRITE and/or greater access to authorized personnel (e.g., systems programming personnel).

Check Content Reference

M

Target Key

5235