STIGQter STIGQter: STIG Summary: zOS FEP for TSS Version: 6 Release: 1 Benchmark Date: 11 Mar 2020:

A password control is not in place to restrict access to the service subsystem via the operator consoles (local and/or remote) and a key-lock switch is not used to protect the modem supporting the remote console of the service subsystem.

DISA Rule

SV-7200r3_rule

Vulnerability Number

V-6905

Group Title

ZFEP0016

Rule Version

ZFEP0016

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

If any of the below procedures are not in place, than correct the situation by documenting the missing procedure(s).

The systems programmer should validate that Control authorization to use service subsystem console (local or remote) by FEP internal security control through password validation. Restrict access to these passwords to the absolutely minimum number of necessary personnel. Use of vendor default passwords is prohibited. Assign different passwords for the local and remote consoles. Disconnect the local/remote console after three unsuccessful attempts to log on. Passwords used by vendor (COMTEN, IBM, CNT, or AMDAHL) service personnel will be changed after any maintenance is done. All passwords will be changed every 90 days. Restrict permission to change passwords only to authorized personnel.

Use a key lock switch on the modem supporting the remote console of the service subsystem to prevent unauthorized access. The key lock switch is only open for scheduled and authorized remote access.

Check Contents

a) Review site documentation to validate that procedures are in place to protect the FEP service subsystem and diskette drive:

- Documents and procedures restricting access to the functions of the service subsystem from the local and/or remote operator consoles (e.g., physical access, password control, key-lock switch of modems, etc.).

b) If a password control is in place to restrict access to the service subsystem via the operator consoles (local and/or remote), there is NO FINDING.

c) If a key-lock switch is used to protect the modem supporting the remote console of the service subsystem, there is NO FINDING.

d) If no procedure exists for any of the above functions of the service subsystem and FEP resources, this is a FINDING.

Vulnerability Number

V-6905

Documentable

False

Rule Version

ZFEP0016

Severity Override Guidance

a) Review site documentation to validate that procedures are in place to protect the FEP service subsystem and diskette drive:

- Documents and procedures restricting access to the functions of the service subsystem from the local and/or remote operator consoles (e.g., physical access, password control, key-lock switch of modems, etc.).

b) If a password control is in place to restrict access to the service subsystem via the operator consoles (local and/or remote), there is NO FINDING.

c) If a key-lock switch is used to protect the modem supporting the remote console of the service subsystem, there is NO FINDING.

d) If no procedure exists for any of the above functions of the service subsystem and FEP resources, this is a FINDING.

Check Content Reference

M

Responsibility

Systems Programmer

Target Key

3359

Comments