SV-223749r604139_rule
V-223749
SRG-OS-000080-GPOS-00048
RACF-JS-000050
CAT II
10
Configure access authorization for resources defined to the WRITER resource class to be restricted to the operators and system programmers on a classified system only.
Define resources in the ACP’s respective WRITER class for each of the following output destinations:
JES2.LOCAL.devicename
JES2.LOCAL.OFFn.*
JES2.LOCAL.OFFn.JT
JES2.LOCAL.OFFn.ST
JES2.LOCAL.PRTn
JES2.LOCAL.PUNn
JES2.NJE.nodename
JES2.RJE.devicename
From the ISPF Command Shell enter:
RL WRITER *
If the RACF resources and/or generic equivalent identified below are defined with access restricted to the appropriate personnel, this is not a finding.
JES2.LOCAL.devicename
JES2.LOCAL.OFFn.*
JES2.LOCAL.OFFn.JT
JES2.LOCAL.OFFn.ST
JES2.LOCAL.PRTn
JES2.LOCAL.PUNn
JES2.NJE.nodename
JES2.RJE.devicename
Note: Examples of appropriate might be access to the offload input sources is limited to systems personnel (e.g., operations staff) as directed by site operations and the site security plan.
V-223749
False
RACF-JS-000050
From the ISPF Command Shell enter:
RL WRITER *
If the RACF resources and/or generic equivalent identified below are defined with access restricted to the appropriate personnel, this is not a finding.
JES2.LOCAL.devicename
JES2.LOCAL.OFFn.*
JES2.LOCAL.OFFn.JT
JES2.LOCAL.OFFn.ST
JES2.LOCAL.PRTn
JES2.LOCAL.PUNn
JES2.NJE.nodename
JES2.RJE.devicename
Note: Examples of appropriate might be access to the offload input sources is limited to systems personnel (e.g., operations staff) as directed by site operations and the site security plan.
M
4101