SV-3900r4_rule
V-3900
ZWAS0040
ZWAS0040
CAT I
10
The IAO will ensure that the CBADMIN user account is removed or not defined to the ACP.
a) Refer to the following report produced by the ACP Data Collection:
ACF2
- ACF2CMDS.RPT(LOGONIDS)
RACF
- RACFCMDS.RPT(LISTUSER)
TSS
- TSSCMDS.RPT(@ACIDS)
Automated Analysis requires Additional Analysis.
Refer to the following report produced by the z/OS Data Collection:
- PDI(ZWAS0040)
b) If the CBADMIN user account is not defined to the ACP, there is NO FINDING.
c) If the CBADMIN user account is defined to ACP and the password has NOT been changed from the vendor default of CBADMIN, this is a FINDING with a severity code of CAT I.
d) If the CBADMIN user account is defined to the ACP and the password has been changed from the vendor default of CBADMIN, this is a FINDING with a severity code of
CAT II.
V-3900
False
ZWAS0040
a) Refer to the following report produced by the ACP Data Collection:
ACF2
- ACF2CMDS.RPT(LOGONIDS)
RACF
- RACFCMDS.RPT(LISTUSER)
TSS
- TSSCMDS.RPT(@ACIDS)
Automated Analysis requires Additional Analysis.
Refer to the following report produced by the z/OS Data Collection:
- PDI(ZWAS0040)
b) If the CBADMIN user account is not defined to the ACP, there is NO FINDING.
c) If the CBADMIN user account is defined to ACP and the password has NOT been changed from the vendor default of CBADMIN, this is a FINDING with a severity code of CAT I.
d) If the CBADMIN user account is defined to the ACP and the password has been changed from the vendor default of CBADMIN, this is a FINDING with a severity code of
CAT II.
M
Information Assurance Officer
3361