STIGQter STIGQter: STIG Summary: IBM z/OS ACF2 Security Technical Implementation Guide Version: 8 Release: 2 Benchmark Date: 23 Apr 2021:

The EXITS GSO record value must specify the module names of site written ACF2 exit routines.

DISA Rule

SV-223467r533198_rule

Vulnerability Number

V-223467

Group Title

SRG-OS-000480-GPOS-00227

Rule Version

ACF2-ES-000490

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the EXITS GSO value to specify the module names of site written ACF2 exit routines.

Specifies the module names of site written ACF2 exit routines.

NOTE: The DSNPOST exit is optional and is not required to be specified in the GSO EXITS record.

DSNPOST(module) SEVPRE(SEVPRE01) SEVPOST(SEVPST01)

Example:
SET C(GSO)
INSERT EXITS DSNPOST(module) SEVPRE(SEVPRE01) SEVPOST(SEVPST01)

F ACF2,REFRESH(EXITS)

NOTE: No other exits are authorized at this time.

NOTE: Local changes will be justified in writing with supporting documentation.

Check Contents

From the ACF Command enter:
SET CONTROL(GSO)
LIST LIKE(EXIT-)

If the GSO EXITS record values conform to the following requirements, this is not a finding.

Specifies the module names of site written ACF2 exit routines.

NOTE: The DSNPOST exit is optional and is not required to be specified in the GSO EXITS record. DSNPOST(module) SEVPRE(SEVPRE01) SEVPOST(SEVPST01)
NOTE: No other exits are authorized at this time.
NOTE: Local changes will be documented in writing with supporting documentation.

If there is any deviation from the above requirements in the GSO EXITS record values, this is a finding.

Vulnerability Number

V-223467

Documentable

False

Rule Version

ACF2-ES-000490

Severity Override Guidance

From the ACF Command enter:
SET CONTROL(GSO)
LIST LIKE(EXIT-)

If the GSO EXITS record values conform to the following requirements, this is not a finding.

Specifies the module names of site written ACF2 exit routines.

NOTE: The DSNPOST exit is optional and is not required to be specified in the GSO EXITS record. DSNPOST(module) SEVPRE(SEVPRE01) SEVPOST(SEVPST01)
NOTE: No other exits are authorized at this time.
NOTE: Local changes will be documented in writing with supporting documentation.

If there is any deviation from the above requirements in the GSO EXITS record values, this is a finding.

Check Content Reference

M

Target Key

4100

Comments