STIGQter STIGQter: STIG Summary: IBM z/OS TSS Security Technical Implementation Guide Version: 8 Release: 2 Benchmark Date: 23 Apr 2021:

IBM z/OS JESNEWS resources must be protected in accordance with security requirements.

DISA Rule

SV-223992r561402_rule

Vulnerability Number

V-223992

Group Title

SRG-OS-000080-GPOS-00048

Rule Version

TSS0-JS-000080

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure access authorization to the JES2.UPDATE.JESNEWS resource in the OPERCMDS class to restrict CONTROL access to the appropriate personnel (i.e., users responsible for maintaining the JES News data set) and all access is logged.

NOTE: JES2 is typically the name of the JES2 subsystem. Refer to the SUBSYS report and locate the entry with the description of PRIMARY JOB ENTRY SUBSYSTEM. The SUBSYSTEM NAME of this entry is the name of the JES2 subsystem.

For Example:

The following command example may be used to allow all valid TOP SECRET users read access to the JES News data set:

TSS PERMIT(ALL) JESSPOOL(localnodeid.jesid.$JESNEWS.*.*.JESNEWS) –
ACCESS(READ)

The following is a sample command to allow production control personnel with a profile ACID of prodacid to update the JES News data set:

TSS PERMIT(prodacid) OPERCMDS(JES2.UPDATE.JESNEWS) -
ACCESS(CONTROL) ACTION(AUDIT)

Check Contents

From the ISPF Command Shell enter:
TSS WHOHAS OPERCMDS(JES2.)
NOTE: JES2 is typically the name of the JES2 subsystem. Refer to the SUBSYS report and locate the entry with the description of PRIMARY JOB ENTRY SUBSYSTEM. The SUBSYSTEM NAME of this entry is the name of the JES2 subsystem.

If access authorization to the JES2.UPDATE.JESNEWS resource in the OPERCMDS class restricts CONTROL access to the appropriate personnel (i.e., users responsible for maintaining the JES News data set) and all access is logged, this is not a finding.

Vulnerability Number

V-223992

Documentable

False

Rule Version

TSS0-JS-000080

Severity Override Guidance

From the ISPF Command Shell enter:
TSS WHOHAS OPERCMDS(JES2.)
NOTE: JES2 is typically the name of the JES2 subsystem. Refer to the SUBSYS report and locate the entry with the description of PRIMARY JOB ENTRY SUBSYSTEM. The SUBSYSTEM NAME of this entry is the name of the JES2 subsystem.

If access authorization to the JES2.UPDATE.JESNEWS resource in the OPERCMDS class restricts CONTROL access to the appropriate personnel (i.e., users responsible for maintaining the JES News data set) and all access is logged, this is not a finding.

Check Content Reference

M

Target Key

4102

Comments