STIGQter STIGQter: STIG Summary: IBM z/OS ACF2 Security Technical Implementation Guide Version: 8 Release: 2 Benchmark Date: 23 Apr 2021:

IBM z/OS user account for the UNIX kernel (OMVS) must be properly defined to the security database.

DISA Rule

SV-223494r533198_rule

Vulnerability Number

V-223494

Group Title

SRG-OS-000104-GPOS-00051

Rule Version

ACF2-ES-000760

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Define the OMVS (IBM default name for USS Kernel), as specified below:

No access to interactive on-line facilities (e.g., TSO, CICS, etc.)
Default group specified as OMVSGRP or STCOMVS
UID(0)
HOME directory specified as "/"
Shell program specified as "/bin/sh"

Check Contents

From the ISPF Command Shell enter:
ACF
SET LID
SET VERBOSE
LIST OMVS SECTION(ALL) PROFILE(OMVS)

If OMVS is defined as follows, this is not a finding.

No access to interactive on-line facilities (e.g., TSO, CICS, etc).
Default group specified as OMVSGRP or STCOMVS
UID(0)
HOME directory specified as “/”
Shell program specified as “/bin/sh”

If OMVS is not defined as specified in above, this is a finding.

Vulnerability Number

V-223494

Documentable

False

Rule Version

ACF2-ES-000760

Severity Override Guidance

From the ISPF Command Shell enter:
ACF
SET LID
SET VERBOSE
LIST OMVS SECTION(ALL) PROFILE(OMVS)

If OMVS is defined as follows, this is not a finding.

No access to interactive on-line facilities (e.g., TSO, CICS, etc).
Default group specified as OMVSGRP or STCOMVS
UID(0)
HOME directory specified as “/”
Shell program specified as “/bin/sh”

If OMVS is not defined as specified in above, this is a finding.

Check Content Reference

M

Target Key

4100

Comments