SV-223514r533198_rule
V-223514
SRG-OS-000134-GPOS-00068
ACF2-ES-000970
CAT I
10
Configure ESM READ and/or greater access rules for ESM files and/or databases as limited to system programmers and/or security personnel, and/or batch jobs that perform ACP maintenance.
READ access can be given to auditors and DASD batch. All accesses to ACP files and/or databases are logged.
Determine all associated ESM security data sets and/or databases.
If the ESM data set rules for ESM security data sets and/or databases restrict READ access to auditors and DASD batch, this is not a finding.
If the ESM data set rules for ESM security data sets and/or databases restrict READ and/or greater access to z/OS systems programming personnel, security personnel, and/or batch jobs that perform ACP maintenance, this is not a finding.
If all (i.e., failures and successes) data set access authorities (i.e., READ, UPDATE, ALTER, and CONTROL) for ACP security data sets and/or databases are logged, this is not a finding.
V-223514
False
ACF2-ES-000970
Determine all associated ESM security data sets and/or databases.
If the ESM data set rules for ESM security data sets and/or databases restrict READ access to auditors and DASD batch, this is not a finding.
If the ESM data set rules for ESM security data sets and/or databases restrict READ and/or greater access to z/OS systems programming personnel, security personnel, and/or batch jobs that perform ACP maintenance, this is not a finding.
If all (i.e., failures and successes) data set access authorities (i.e., READ, UPDATE, ALTER, and CONTROL) for ACP security data sets and/or databases are logged, this is not a finding.
M
4100