SV-223463r533198_rule
V-223463
SRG-OS-000063-GPOS-00032
ACF2-ES-000440
CAT I
10
Configure access rules for SYS1.PARMLIB as follows:
Systems programming personnel will be authorized to update and alter the SYS1.PARMLIB concatenation.
Domain level security administrators can be authorized to update the SYS1.PARMLIB concatenation.
System Level Started Tasks, authorized Data Center personnel, and auditor can be authorized read access by the ISSO.
All update and alter access is logged.
Execute a data set list of access to SYS1.PARMLIB.
If the ESM data set rules for SYS1.PARMLIB allow inappropriate (e.g., global READ) access.
If data set rules for SYS1.PARMLIB do not restrict READ, UPDATE, and ALTER access to only systems programming personnel, this is a finding.
If data set rules for SYS1.PARMLIB do not restrict READ and UPDATE access to only domain level security administrators, this is a finding.
If data set rules for SYS1.PARMLIB do not restrict READ access to only system Level Started Tasks, authorized Data Center personnel, and auditors, this is a finding.
If data set rules for SYS1.PARMLIB do not specify that all (i.e., failures and successes) UPDATE and/or ALTER access will be logged, this is a finding.
V-223463
False
ACF2-ES-000440
Execute a data set list of access to SYS1.PARMLIB.
If the ESM data set rules for SYS1.PARMLIB allow inappropriate (e.g., global READ) access.
If data set rules for SYS1.PARMLIB do not restrict READ, UPDATE, and ALTER access to only systems programming personnel, this is a finding.
If data set rules for SYS1.PARMLIB do not restrict READ and UPDATE access to only domain level security administrators, this is a finding.
If data set rules for SYS1.PARMLIB do not restrict READ access to only system Level Started Tasks, authorized Data Center personnel, and auditors, this is a finding.
If data set rules for SYS1.PARMLIB do not specify that all (i.e., failures and successes) UPDATE and/or ALTER access will be logged, this is a finding.
M
4100