STIGQter STIGQter: STIG Summary: IBM z/OS ACF2 Security Technical Implementation Guide Version: 8 Release: 2 Benchmark Date: 23 Apr 2021:

The number of ACF2 users granted the special privilege CONSOLE must be justified.

DISA Rule

SV-223425r533198_rule

Vulnerability Number

V-223425

Group Title

SRG-OS-000080-GPOS-00048

Rule Version

ACF2-ES-000040

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Define the CONSOLE attribute with minimum access and it is controlled and documented.

Documentation providing justification for access is maintained and filed with the ISSO and that unjustified access is removed.

Check Contents

From the ISPF Command Shell enter:
ACF
SET LID
SET VERBOSE
LIST IF(ACCTPRIV OR CONSOLE OR OPERATOR OR MOUNT)

If the number of users granted the special privilege CONSOLE is strictly controlled (issued on an as-needed basis), this is not a finding.

If the number of users granted the special privilege CONSOLE is not strictly controlled (issued on an as-needed basis), this is a finding.

Vulnerability Number

V-223425

Documentable

False

Rule Version

ACF2-ES-000040

Severity Override Guidance

From the ISPF Command Shell enter:
ACF
SET LID
SET VERBOSE
LIST IF(ACCTPRIV OR CONSOLE OR OPERATOR OR MOUNT)

If the number of users granted the special privilege CONSOLE is strictly controlled (issued on an as-needed basis), this is not a finding.

If the number of users granted the special privilege CONSOLE is not strictly controlled (issued on an as-needed basis), this is a finding.

Check Content Reference

M

Target Key

4100

Comments