STIGQter STIGQter: STIG Summary: IBM z/OS TSS Security Technical Implementation Guide Version: 8 Release: 2 Benchmark Date: 23 Apr 2021:

IBM z/OS JESSPOOL resources must be protected in accordance with security requirements.

DISA Rule

SV-223991r561402_rule

Vulnerability Number

V-223991

Group Title

SRG-OS-000080-GPOS-00048

Rule Version

TSS0-JS-000070

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Review the JES2 parameters to determine the localnodeid by searching for OWNNODE in the NJEDEF statement, and then searching for NODE(nnnn) (where nnnn is the value specified by OWNNODE). The NAME parameter value specified on this NODE statement is the localnodeid.

The following command may be used to establish default protection for resources defined to the JESSPOOL resource class:

TSS ADDTO(deptacid) JESSPOOL(localnodeid.)

Due to the protection established with the previous command, the following command should be issued to ensure users are able to access their own spool data:

TSS PERMIT(ALL) JESSPOOL(localnodeid.%) ACCESS(ALL)

Check Contents

Refer the JES2PARM member of SYS1.PARMLIB. Review the JESSPOOL resource in the JESINPUT resource class:

NOTE: If the JESSPOOL resource is not defined within the JES2 parameters, the resource in the JESINPUT resource class does not have to be owned.

From the ISPF Command Shell enter:

TSS WHOOWNS JESINPUT(JESSPOOL)

If the JESSPOOL resource is owned by generic and/or fully qualified entries in the JESINPUT resource class, this is not a finding.

Vulnerability Number

V-223991

Documentable

False

Rule Version

TSS0-JS-000070

Severity Override Guidance

Refer the JES2PARM member of SYS1.PARMLIB. Review the JESSPOOL resource in the JESINPUT resource class:

NOTE: If the JESSPOOL resource is not defined within the JES2 parameters, the resource in the JESINPUT resource class does not have to be owned.

From the ISPF Command Shell enter:

TSS WHOOWNS JESINPUT(JESSPOOL)

If the JESSPOOL resource is owned by generic and/or fully qualified entries in the JESINPUT resource class, this is not a finding.

Check Content Reference

M

Target Key

4102

Comments