SV-223449r533198_rule
V-223449
SRG-OS-000080-GPOS-00048
ACF2-ES-000280
CAT I
10
Review access authorization to critical system files. Evaluate the impact of correcting the deficiency. Develop a plan of action and implement the changes required to protect APF Authorized Libraries.
Configure Update and Allocate access to all APF-authorized libraries to be limited to system programmers only and all update and alter access is logged.
From Any ISPF input line, enter:
TSO ISRDDN APF
If all of the below are untrue, this is not a finding.
If any of the below is true, this is a finding.
-The ACP data set rules for APF libraries do not restrict UPDATE and/or ALTER access to only z/OS systems programming personnel.
-The ACP data set rules for APF libraries do not specify that all (i.e., failures and successes) UPDATE and/or ALTER access will be logged.
V-223449
False
ACF2-ES-000280
From Any ISPF input line, enter:
TSO ISRDDN APF
If all of the below are untrue, this is not a finding.
If any of the below is true, this is a finding.
-The ACP data set rules for APF libraries do not restrict UPDATE and/or ALTER access to only z/OS systems programming personnel.
-The ACP data set rules for APF libraries do not specify that all (i.e., failures and successes) UPDATE and/or ALTER access will be logged.
M
4100