STIGQter STIGQter: STIG Summary: IBM z/OS ACF2 Security Technical Implementation Guide Version: 8 Release: 2 Benchmark Date: 23 Apr 2021:

IBM z/OS user account for the UNIX (RMFGAT) must be properly defined.

DISA Rule

SV-223495r533198_rule

Vulnerability Number

V-223495

Group Title

SRG-OS-000104-GPOS-00051

Rule Version

ACF2-ES-000770

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Define the RMFGAT user account as specified below:
Default group specified as OMVSGRP or STCOMVS
A unique, non-zero UID
HOME directory specified as “/”
Shell program specified as “/bin/sh”

Check Contents

RMFGAT is the userid for the Resource Measurement Facility (RMF) Monitor III Gatherer. If RMFGAT is not define, this is Not Applicable.
From the ISPF Command Shell enter:
ACF
SET LID
SET VERBOSE
LIST RMFGAT SECTION(ALL) PROFILE(OMVS)

If RMFGAT is defined as follows, this is not a finding:
Default group specified as OMVSGRP or STCOMVS
A unique, non-zero UID
HOME directory specified as “/”
Shell program specified as “/bin/sh”

Vulnerability Number

V-223495

Documentable

False

Rule Version

ACF2-ES-000770

Severity Override Guidance

RMFGAT is the userid for the Resource Measurement Facility (RMF) Monitor III Gatherer. If RMFGAT is not define, this is Not Applicable.
From the ISPF Command Shell enter:
ACF
SET LID
SET VERBOSE
LIST RMFGAT SECTION(ALL) PROFILE(OMVS)

If RMFGAT is defined as follows, this is not a finding:
Default group specified as OMVSGRP or STCOMVS
A unique, non-zero UID
HOME directory specified as “/”
Shell program specified as “/bin/sh”

Check Content Reference

M

Target Key

4100

Comments