SV-7191r3_rule
V-6896
ZCICA025
ZCICA025
CAT II
10
The Systems Programmer and IAO will ensure the ACF2/CICS parameter PROTLIST is not coded.
Browse the ACF2/CICS data set allocated by the ACF2PARM DD statement in the JCL of each CICS procedure.
Make sure the PROTLIST parameter is not specified for all CICS regions.
a) Refer to the following report produced by the z/OS Data Collection:
- EXAM.RPT(CICSPROC)
Refer to the CICS Systems Programmer Worksheets filled out from previous vulnerability ZCIC0010.
b) Browse the ACF2/CICS data set allocated by the ACF2PARM DD statement in the JCL of each CICS procedure.
c) If the PROTLIST parameter is not specified for all CICS regions, there is NO FINDING.
d) If the PROTLIST parameter is specified for any CICS region, this is a FINDING.
V-6896
False
ZCICA025
a) Refer to the following report produced by the z/OS Data Collection:
- EXAM.RPT(CICSPROC)
Refer to the CICS Systems Programmer Worksheets filled out from previous vulnerability ZCIC0010.
b) Browse the ACF2/CICS data set allocated by the ACF2PARM DD statement in the JCL of each CICS procedure.
c) If the PROTLIST parameter is not specified for all CICS regions, there is NO FINDING.
d) If the PROTLIST parameter is specified for any CICS region, this is a FINDING.
M
Systems Programmer
198