STIGQter STIGQter: STIG Summary: IBM z/OS TSS Security Technical Implementation Guide Version: 8 Release: 2 Benchmark Date: 23 Apr 2021:

IBM z/OS RJE workstations and NJE nodes must be controlled in accordance with STIG requirements.

DISA Rule

SV-223986r561402_rule

Vulnerability Number

V-223986

Group Title

SRG-OS-000080-GPOS-00048

Rule Version

TSS0-JS-000020

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Ensure associated USERIDs exist for all RJE/NJE sources and review the authorizations for these remote facilities. Develop a plan of action and implement the changes as required by the OS/390 STIG.

Check Contents

Refer to SYS1.PARMLIB (JES2PARM)
For each node entry

If all JES2 defined NJE nodes and RJE workstations have a profile defined in the IBMFAC resource class, this is not a finding.

Notes: Nodename is the NAME parameter value specified on the NODE statement. Review the JES2 parameters for NJE node definitions by searching for "NODE(" in the report.
Workstation is RMTnnnn, where nnnn is the number on the RMT statement. Review the JES2 parameters for RJE workstation definitions by searching for "RMT(" in the report.
NJE. and RJE. definitions will force logonid and password protection of all NJE and RJE connections respectively. This method is acceptable in lieu of using discrete profiles.

If any JES2 defined NJE node or RJE workstation is not owned in the IBMFAC class, this is a finding.

Vulnerability Number

V-223986

Documentable

False

Rule Version

TSS0-JS-000020

Severity Override Guidance

Refer to SYS1.PARMLIB (JES2PARM)
For each node entry

If all JES2 defined NJE nodes and RJE workstations have a profile defined in the IBMFAC resource class, this is not a finding.

Notes: Nodename is the NAME parameter value specified on the NODE statement. Review the JES2 parameters for NJE node definitions by searching for "NODE(" in the report.
Workstation is RMTnnnn, where nnnn is the number on the RMT statement. Review the JES2 parameters for RJE workstation definitions by searching for "RMT(" in the report.
NJE. and RJE. definitions will force logonid and password protection of all NJE and RJE connections respectively. This method is acceptable in lieu of using discrete profiles.

If any JES2 defined NJE node or RJE workstation is not owned in the IBMFAC class, this is a finding.

Check Content Reference

M

Target Key

4102

Comments