SV-223594r533198_rule
V-223594
SRG-OS-000080-GPOS-00048
ACF2-SM-000020
CAT II
10
Note: The resource type, resources, and/or resource prefixes identified below are examples of a possible installation. The actual resource type, resources, and/or resource prefixes are determined when the product is actually installed on a system through the product’s installation guide and can be site specific.
Refer to the chapter titled "Protecting the Storage Management Subsystem" in the IBM z/OS DFSMSdfp Storage Administration Guide.
Use SMS Program Resources tables to determine the resources, access requirements for SMS Program Resources. Ensure the guidelines for the resource type, resources, and/or generic equivalent specified.
The ACF2 resources as designated in the above table are defined with a default access of PREVENT.
The ACF2 resource access authorizations restrict access to the appropriate personnel as designated in the above tables.
The following commands are provided as a sample for implementing resource controls:
$KEY(ACBFUTO2) TYPE(PGM)
UID(********) ALLOW
UID(*) PREVENT
F ACF2,REBUILD(PGM)
Refer to the load modules residing in the following Load libraries to determine Program resource definitions:
v SYS1.DGTLLIB for DFSMSdfp/ISMF
v SYS1.DGTLLIB for DFSMSdss/ISMF
v SYS1.DFQLLIB for DFSMShsm
If the installation moves these modules to another load library the installation-defined load library must be used in the program protection.
If the RACF resources are defined with a default access of NONE, this is not a finding.
If the RACF resource access authorizations restrict access to the appropriate personnel, this is not a finding.
Refer to the chapter titled “Protecting the Storage Management Subsystem” in the IBM z/OS DFSMSdfp Storage Administration Guide to assist with guidance on appropriate access.
V-223594
False
ACF2-SM-000020
Refer to the load modules residing in the following Load libraries to determine Program resource definitions:
v SYS1.DGTLLIB for DFSMSdfp/ISMF
v SYS1.DGTLLIB for DFSMSdss/ISMF
v SYS1.DFQLLIB for DFSMShsm
If the installation moves these modules to another load library the installation-defined load library must be used in the program protection.
If the RACF resources are defined with a default access of NONE, this is not a finding.
If the RACF resource access authorizations restrict access to the appropriate personnel, this is not a finding.
Refer to the chapter titled “Protecting the Storage Management Subsystem” in the IBM z/OS DFSMSdfp Storage Administration Guide to assist with guidance on appropriate access.
M
4100