STIGQter STIGQter: STIG Summary: z/OS Compuware Abend-AID for TSS STIG Version: 6 Release: 6 Benchmark Date: 27 Jul 2018:

Compuware Abend-AID external security options must be specified properly.

DISA Rule

SV-43205r2_rule

Vulnerability Number

V-18014

Group Title

ZB000040

Rule Version

ZAID0040

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

In the data set specified in the CWPARM DD statement from the ECC started task procedure, specify the parameter values for each component in the respective members as follows:

Member Name: AABD00 - Abend-AID batch dump capture address space
EXTERNAL_SECURITY_ENABLED=YES
Member Name: AATD00 - Abend-AID CICS Transaction Dump Capture Address Space
EXTERNAL_SECURITY_ENABLED=YES
Member Name: AAVW00 - Abend-AID viewing server
EXTERNAL_SECURITY_ENABLED=YES

Check Contents

Examine the Enterprise Common Components (ECC) started task procedure. (This can usually be found in the system PROCLIBs). Refer to the contents of the data set specified in the CWPARM DD statement.

Automated Analysis
Refer to the following report produced by the z/OS Data Collection:

- PDI(ZAID0040)

Review the Member name listed.

If the following is specified for each component, this is not a finding.
Member Name: AABD00 - Abend-AID batch dump capture address space
EXTERNAL_SECURITY_ENABLED=YES
Member Name: AATD00 - Abend-AID CICS Transaction Dump Capture Address Space
EXTERNAL_SECURITY_ENABLED=YES
Member Name: AAVW00 - Abend-AID viewing server
EXTERNAL_SECURITY_ENABLED=YES

Vulnerability Number

V-18014

Documentable

False

Rule Version

ZAID0040

Severity Override Guidance

Examine the Enterprise Common Components (ECC) started task procedure. (This can usually be found in the system PROCLIBs). Refer to the contents of the data set specified in the CWPARM DD statement.

Automated Analysis
Refer to the following report produced by the z/OS Data Collection:

- PDI(ZAID0040)

Review the Member name listed.

If the following is specified for each component, this is not a finding.
Member Name: AABD00 - Abend-AID batch dump capture address space
EXTERNAL_SECURITY_ENABLED=YES
Member Name: AATD00 - Abend-AID CICS Transaction Dump Capture Address Space
EXTERNAL_SECURITY_ENABLED=YES
Member Name: AAVW00 - Abend-AID viewing server
EXTERNAL_SECURITY_ENABLED=YES

Check Content Reference

M

Responsibility

Systems Programmer

Target Key

2344

Comments