SV-257r2_rule
V-257
RACF0280
RACF0280
CAT II
10
The IAO will ensure that CMDVIOL SETROPTS value is active and set to log RACF commands violations.
Evaluate the impact associated with implementation of the control option. Develop a plan of action to implement the control option as specified in the example below:
The RACF Command SETR LIST will show the status of RACF Controls including a list of ATTRIBUTES.
(1) Command Violation Logging is activated with the command SETR CMDVIOL.
a) Refer to the following report produced by the RACF Data Collection:
- RACFCMDS.RPT(SETROPTS)
Automated Analysis
Refer to the following report produced by the RACF Data Collection:
- PDI(RACF0280)
b) If the CMDVIOL value is listed as one of the ATTRIBUTES, there is NO FINDING.
c) If the CMDVIOL value is not listed as one of the ATTRIBUTES, this is a FINDING.
V-257
False
RACF0280
a) Refer to the following report produced by the RACF Data Collection:
- RACFCMDS.RPT(SETROPTS)
Automated Analysis
Refer to the following report produced by the RACF Data Collection:
- PDI(RACF0280)
b) If the CMDVIOL value is listed as one of the ATTRIBUTES, there is NO FINDING.
c) If the CMDVIOL value is not listed as one of the ATTRIBUTES, this is a FINDING.
M
Information Assurance Officer
197