STIGQter STIGQter: STIG Summary: IBM z/OS TSS Security Technical Implementation Guide Version: 8 Release: 2 Benchmark Date: 23 Apr 2021:

CA-TSS must use propagation control to eliminate ACID inheritance.

DISA Rule

SV-223960r561402_rule

Vulnerability Number

V-223960

Group Title

SRG-OS-000326-GPOS-00126

Rule Version

TSS0-ES-000870

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Ensure an associated ACID exists for all batch jobs and propagation control is being used. Evaluate the impact of correcting the deficiency. Develop a plan of action and implement the changes as required.

The following Example shows the CONTROL-M STC ACID being owned to the PROPCNTL resource class:
TSS ADD(deptacid) PROPCNTL(control-m-acid)

Check Contents

From the ISPF Command Shell enter:
TSS MODIFY FACILITY(ALL)

enter
TSS MODIFY FACILITY(<FACILITY>)

If no Facility is defined with both the "MULTIUSER" and "ASUBM" attributes further analysis is not needed.

For each Facility with "MULTIUSER" and "ASUBM" attribute, review the @ACIDS report to determine which ACID(s) has (have) the following:

-A Master Facility of the Facility with "MULTIUSER" and "ASUBM" attribute, and,
-The Facility of "BATCH"

If each ACID that has the Master Facility of the Facility with "MULTIUSER" and "ASUBM" attribute and the Facility of "BATCH" is defined to the "PROPCNTL" resource class, this is not a finding.

Vulnerability Number

V-223960

Documentable

False

Rule Version

TSS0-ES-000870

Severity Override Guidance

From the ISPF Command Shell enter:
TSS MODIFY FACILITY(ALL)

enter
TSS MODIFY FACILITY(<FACILITY>)

If no Facility is defined with both the "MULTIUSER" and "ASUBM" attributes further analysis is not needed.

For each Facility with "MULTIUSER" and "ASUBM" attribute, review the @ACIDS report to determine which ACID(s) has (have) the following:

-A Master Facility of the Facility with "MULTIUSER" and "ASUBM" attribute, and,
-The Facility of "BATCH"

If each ACID that has the Master Facility of the Facility with "MULTIUSER" and "ASUBM" attribute and the Facility of "BATCH" is defined to the "PROPCNTL" resource class, this is not a finding.

Check Content Reference

M

Target Key

4102

Comments