STIGQter STIGQter: STIG Summary: z/OS BMC CONTROL-O for TSS STIG Version: 6 Release: 7 Benchmark Date: 26 Oct 2018:

BMC CONTROL-O configuration/parameter values are not specified properly.

DISA Rule

SV-32006r1_rule

Vulnerability Number

V-22689

Group Title

ZB000041

Rule Version

ZCTO0041

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

The BMC CONTROL-O Systems programmer will verify that any configuration/parameters that are required to control the security of the product are properly configured and syntactically correct. Set the standard values for the BMC CONTROL-O security parameters for the specific ACP environment along with additional IOA security parameters with standard values as documented below.

Keyword Value
RUNTDFT OWNER
RUNTCACH 100
AUTOMLOG V

Check Contents

Refer to the following applicable reports produced by the z/OS Data Collection:

- IOA.RPT(CTOPARM)

Automated Analysis
Refer to the following report produced by the z/OS Data Collection:

- PDI(ZCTO0041)

The following keywords will have the specified values in the BMC CONTROL-O security parameter member:

Keyword Value
RUNTDFT OWNER
RUNTCACH 100
AUTOMLOG V

Vulnerability Number

V-22689

Documentable

False

Rule Version

ZCTO0041

Severity Override Guidance

Refer to the following applicable reports produced by the z/OS Data Collection:

- IOA.RPT(CTOPARM)

Automated Analysis
Refer to the following report produced by the z/OS Data Collection:

- PDI(ZCTO0041)

The following keywords will have the specified values in the BMC CONTROL-O security parameter member:

Keyword Value
RUNTDFT OWNER
RUNTCACH 100
AUTOMLOG V

Check Content Reference

M

Responsibility

Systems Programmer

Target Key

2001

Comments