STIGQter STIGQter: STIG Summary: IBM z/OS ACF2 Security Technical Implementation Guide Version: 8 Release: 2 Benchmark Date: 23 Apr 2021:

ACF2 MAINT GSO record value if specified must be restricted to production storage management user.

DISA Rule

SV-223489r533198_rule

Vulnerability Number

V-223489

Group Title

SRG-OS-000368-GPOS-00154

Rule Version

ACF2-ES-000710

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the MAINT GSO value to be specified as restricted to production storage management user accounts and programs.

Specifies the logonid, program, and library combinations used for system maintenance functions.
NOTE: For logonids that match environments described in records, no SMF logging records will be created.
NOTE: Entries will be restricted to production storage management user accounts and programs.

Check Contents

From the ACF Command screen enter:
SET CONTROL(GSO)
LIST LIKE(MAINT-)

If the GSO MAINT record values conform to the following requirements, this is not a finding.

Specifies the logonid, program, and library combinations used for system maintenance functions.
NOTE: For logonids that match environments described in records, no SMF logging records will be created.
NOTE: Entries will be restricted to production storage management user accounts and programs.

If there is any deviation from the above requirements in the GSO MAINT record values, this is a finding.

Vulnerability Number

V-223489

Documentable

False

Rule Version

ACF2-ES-000710

Severity Override Guidance

From the ACF Command screen enter:
SET CONTROL(GSO)
LIST LIKE(MAINT-)

If the GSO MAINT record values conform to the following requirements, this is not a finding.

Specifies the logonid, program, and library combinations used for system maintenance functions.
NOTE: For logonids that match environments described in records, no SMF logging records will be created.
NOTE: Entries will be restricted to production storage management user accounts and programs.

If there is any deviation from the above requirements in the GSO MAINT record values, this is a finding.

Check Content Reference

M

Target Key

4100

Comments