STIGQter STIGQter: STIG Summary: z/OS CA 1 Tape Management for TSS STIG Version: 6 Release: 8 Benchmark Date: 25 Oct 2019:

CA 1 Tape Management system password will be changed from the default.

DISA Rule

SV-40107r1_rule

Vulnerability Number

V-22689

Group Title

ZB000041

Rule Version

ZCA10041

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

The systems programmer/IAO will ensure that the CA 1 system password is changed from the vendor default system password.

Verify upon installation that the password is not the same as the default password and user distributed with the original installation default.

For r11.5 and below refer to offset x'18' from the beginning of module TMSTMVT.

For r12.0 and above refer to the SHUTDWN option specified in the TMOOPTxx. The TMOOPTxx member is specified in the TMOSYSxx member in the data set allocated by the TMSPARM DD statement in the TMSINIT STC.

NOTE: The default system password for CA 1 provided by CA is CA1(TMS). The default system passwords provided by SSO are SSOCA1DF and SSOC@1DF.

Check Contents

Refer to the following report produced by the z/OS Data Collection:

- CA1RPT(TMSTMVT) – for r11.5 and below
- CA1RPT(TMOOPTxx) – for r12.0 and above

Automated Analysis
Refer to the following report produced by the z/OS Data Collection:

- PDI(ZCA10041)

For r11.5 and below refer to offset x'18' from the beginning of module TMSTMVT. For r12.0 and above refer to the SHUTDWN option specified in the TMOOPTxx. The TMOOPTxx member is specified in the TMOSYSxx member in the data set allocated by the TMSPARM DD statement in the TMSINIT STC. If the default CA 1 system password is not being utilized, this is not a finding.

NOTE: The default system password for CA 1 provided by CA is CA1(TMS). The default system passwords provided by SSO are SSOCA1DF and SSOC@1DF.

Vulnerability Number

V-22689

Documentable

False

Rule Version

ZCA10041

Severity Override Guidance

Refer to the following report produced by the z/OS Data Collection:

- CA1RPT(TMSTMVT) – for r11.5 and below
- CA1RPT(TMOOPTxx) – for r12.0 and above

Automated Analysis
Refer to the following report produced by the z/OS Data Collection:

- PDI(ZCA10041)

For r11.5 and below refer to offset x'18' from the beginning of module TMSTMVT. For r12.0 and above refer to the SHUTDWN option specified in the TMOOPTxx. The TMOOPTxx member is specified in the TMOSYSxx member in the data set allocated by the TMSPARM DD statement in the TMSINIT STC. If the default CA 1 system password is not being utilized, this is not a finding.

NOTE: The default system password for CA 1 provided by CA is CA1(TMS). The default system passwords provided by SSO are SSOCA1DF and SSOC@1DF.

Check Content Reference

M

Responsibility

Systems Programmer

Target Key

2189

Comments