STIGQter STIGQter: STIG Summary: IBM z/OS TSS Security Technical Implementation Guide Version: 8 Release: 2 Benchmark Date: 23 Apr 2021:

IBM z/OS JES2 output devices must be controlled in accordance with the proper security requirements.

DISA Rule

SV-223989r561402_rule

Vulnerability Number

V-223989

Group Title

SRG-OS-000080-GPOS-00048

Rule Version

TSS0-JS-000050

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Ensure the following items are in effect:

-The JES2. resource is owned in the WRITER resource class.

For Example:
The following command may be used to establish default protection for resources defined to the WRITER resource class:
TSS ADDTO(deptacid) WRITER(JES2.)

-The ownership of all WRITER resources is appropriate.

Grant read access to authorized users for each of the following WRITER resource class output destinations:

JES2.LOCAL.devicename
JES2.LOCAL.OFF*.JT
JES2.LOCAL.OFF*.ST
JES2.LOCAL.PRT*
JES2.LOCAL.PUN*
JES2.NJE.nodename
JES2.RJE.devicename

The following is an example of granting operators with a profile ACID of jesopracid permission to off load SYSOUT data sets into any SPOOL off load processor after obtaining permission from the ISSO:

TSS PERMIT(jesopracid) WRITER(JES2.LOCAL.OFF*.ST) -
ACCESS(READ) ACTION(AUDIT)

The resource definition should be generic if all of the resources of the same type have identical access controls (e.g., if all off load transmitters are equivalent).

Check Contents

Refer the JES2PARM member of SYS1.PARMLIB
Review the WRITER resource in the JESINPUT resource class:

NOTE: If the WRITER resource is not defined within the JES2 parameters, the resource in the JESINPUT resource class does not have to be owned.

From the ISPF Command Shell enter:
TSS WHOOWNS JESINPUT(WRITER)

If the WRITER resource is owned by generic and/or fully qualified entries in the JESINPUT resource class, this is not a finding.

Vulnerability Number

V-223989

Documentable

False

Rule Version

TSS0-JS-000050

Severity Override Guidance

Refer the JES2PARM member of SYS1.PARMLIB
Review the WRITER resource in the JESINPUT resource class:

NOTE: If the WRITER resource is not defined within the JES2 parameters, the resource in the JESINPUT resource class does not have to be owned.

From the ISPF Command Shell enter:
TSS WHOOWNS JESINPUT(WRITER)

If the WRITER resource is owned by generic and/or fully qualified entries in the JESINPUT resource class, this is not a finding.

Check Content Reference

M

Target Key

4102

Comments