SV-223570r533198_rule
V-223570
SRG-OS-000138-GPOS-00069
ACF2-OS-000350
CAT II
10
Configure all identified volumes of shared DASD to bel valid within the following.
HMC
VM
z/OS
If the shared volume(s) are valid and systems having access to these shared volume(s) are valid, map disk/VTOC list to obtain data sets on the shared volume(s). From this list obtain a list of sensitive and critical system data sets that are found on the shared volume(s). Ensure that the data sets are justified to be shared on the system and to reside on the shared volume(s).
The ISSO will review all access requirements to validate that sensitive and critical system data sets are protected from unauthorized access across all systems that have access to the shared volume(s), thereby protecting the data set(s) whether the data set(s) are used or not used on the systems that have the shared volume(s) available to them.
Check HMC, VM, and z/OS on how to validate and determine a DASD volume(s) is shared.
Note: In VM issue the command "QUEUE DASD SYSTEM" this display will show shared volume(s) and indicates the number of systems sharing the volume.
Validate all machines that require access to these shared volume(s) have the volume(s) mounted.
Obtain a map or list VTOC of the shared volume(s).
Check if shared volume(s) contain any critical or sensitive data sets.
Identify shared and critical or sensitive data sets on the system being audited. These data sets can be APF, LINKLIST, LPA, Catalogs, etc, as well as product data sets.
If all of the critical or sensitive data sets identified on shared volume(s) are protected and justified to be on shared volume(s), this is not a finding.
List critical or sensitive data sets are possible security breaches, if not justified and not protected on systems having access to the data set(s) and on shared volume(s).
V-223570
False
ACF2-OS-000350
Check HMC, VM, and z/OS on how to validate and determine a DASD volume(s) is shared.
Note: In VM issue the command "QUEUE DASD SYSTEM" this display will show shared volume(s) and indicates the number of systems sharing the volume.
Validate all machines that require access to these shared volume(s) have the volume(s) mounted.
Obtain a map or list VTOC of the shared volume(s).
Check if shared volume(s) contain any critical or sensitive data sets.
Identify shared and critical or sensitive data sets on the system being audited. These data sets can be APF, LINKLIST, LPA, Catalogs, etc, as well as product data sets.
If all of the critical or sensitive data sets identified on shared volume(s) are protected and justified to be on shared volume(s), this is not a finding.
List critical or sensitive data sets are possible security breaches, if not justified and not protected on systems having access to the data set(s) and on shared volume(s).
M
4100