STIGQter STIGQter: STIG Summary: z/OS IBM CICS Transaction Server for RACF STIG Version: 6 Release: 6 Benchmark Date: 24 Apr 2020:

External RACF Classes are not active for CICS transaction checking.

DISA Rule

SV-301r3_rule

Vulnerability Number

V-301

Group Title

ZCICR021

Rule Version

ZCICR038

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Review each CICS SIT to ensure each region has a unique resource class or resource prefix specified.

1. The resources classes are activated in RACF using the following command: SETR CLASSACT(<classname>)

Check Contents

a) Refer to the following report produced by the RACF Data Collection:

- RACFCMDS.RPT(SETROPTS)

Refer to the CICS Systems Programmer Worksheets filled out from previous vulnerability ZCIC0010.

b) Ensure each CICS transaction resource class pair are active.

c) If (b) is true, there is NO FINDING.

d) If (b) is untrue, this is a FINDING.

Vulnerability Number

V-301

Documentable

False

Rule Version

ZCICR038

Severity Override Guidance

a) Refer to the following report produced by the RACF Data Collection:

- RACFCMDS.RPT(SETROPTS)

Refer to the CICS Systems Programmer Worksheets filled out from previous vulnerability ZCIC0010.

b) Ensure each CICS transaction resource class pair are active.

c) If (b) is true, there is NO FINDING.

d) If (b) is untrue, this is a FINDING.

Check Content Reference

M

Responsibility

Information Assurance Officer

Target Key

197

Comments