STIGQter STIGQter: STIG Summary: z/OS BMC MAINVIEW for z/OS for ACF2 STIG Version: 6 Release: 8 Benchmark Date: 27 Oct 2017:

BMC Mainview for z/OS Resource Class will be defined or active in the ACP.

DISA Rule

SV-33844r1_rule

Vulnerability Number

V-18011

Group Title

ZB000038

Rule Version

ZMVZA038

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

The IAO will use SAF security to define and protect the Products resouce class(es).

Ensure that the following GSO CLASMAP record entry(ies) is (are) defined:

CLASMAP.class RESOURCE(class) RSRCTYPE(type) ENTITYLN(39)

Example:

SET C(GSO)
LIST CLASMAP.BMCVIEW
INSERT CLASMAP.BMCVIEW ENTITYLN(39) RESOURCE(BMCVIEW) RSRCTYPE(BBM)

F ACF2,REFRESH(CLASMAP)

Ensure that the following GSO SAFDEF record entry(ies) is (are) defined:

SAFDEF.ssid ID(BBCS) MODE(GLOBAL)REP RACROUTE(SUBSYS=ssid REQSTOR=-)

Example:

ACF
SET C(GSO)
LIST SAFDEF.ssid
INSERT SAFDEF.ssid ID(BBCS) MODE(GLOBAL)REP RACROUTE(SUBSYS=ssid REQSTOR=-)

F ACF2,REFRESH(SAFDEF)

Check Contents

Refer to the following report produced by the ACF2 Data Collection:

- ACF2CMDS.RPT(ACFGSO)

Ensure that the following GSO CLASMAP record entries are defined:

CLASMAP.class RESOURCE(class) RSRCTYPE(type) ENTITYLN(39)

Ensure that the following GSO SAFDEF record entries are defined:

INSERT SAFDEF.ssid ID(BBCS) MODE(GLOBAL)REP -
RACROUTE(SUBSYS=ssid REQSTOR=-)

Vulnerability Number

V-18011

Documentable

False

Rule Version

ZMVZA038

Severity Override Guidance

Refer to the following report produced by the ACF2 Data Collection:

- ACF2CMDS.RPT(ACFGSO)

Ensure that the following GSO CLASMAP record entries are defined:

CLASMAP.class RESOURCE(class) RSRCTYPE(type) ENTITYLN(39)

Ensure that the following GSO SAFDEF record entries are defined:

INSERT SAFDEF.ssid ID(BBCS) MODE(GLOBAL)REP -
RACROUTE(SUBSYS=ssid REQSTOR=-)

Check Content Reference

M

Responsibility

Information Assurance Officer

Target Key

2093

Comments