SV-7263r4_rule
V-6962
ZWMQ0052
ZWMQ0052
CAT II
10
Ensure all connections to MQSeries/WebSphere MQ resources are restricted using connection security.
Ensure the following connection resources defined to TYPE(MQK) (i.e., MQCONN resource class):
Resource Authorized Users
ssid.BATCH TSO and batch job userids
ssid.CICS CICS region userids
ssid.IMS IMS region userids
ssid.CHIN Channel initiator userids
NOTE: ssid is the queue manager name (a.k.a., subsystem identifier).
For all connection resources defined to TYPE(MQK), ensure the following items are in effect:
Access authorization to these connections restricts access to the appropriate users as indicated above.
All access FAILURE is logged.
Example:
$KEY(ssid) TYPE(MQK)
BATCH UID(STCssid) SERVICE(READ)
BATCH UID(syspaudt) SERVICE(READ)
BATCH UID(*) PREVENT
CHIN UID(STCssidCHIN) SERVICE(READ)
CHIN UID(*) PREVENT
CICS UID(*) PREVENT
IMS UID(*) PREVENT
a) Refer to the following report produced by the ACF2 Data Collection:
- SENSITVE.RPT(MQCONN)
- ACF2CMDS.RPT(RESOURCE) – Alternate report
b) Review the following connection resources defined to TYPE(MQK) (i.e., MQCONN resource class):
Resource Authorized Users
ssid.BATCH TSO and batch job userids
ssid.CICS CICS region userids
ssid.IMS IMS region userids
ssid.CHIN Channel initiator userids
NOTE: ssid is the queue manager name (a.k.a., subsystem identifier).
c) For all connection resources defined to TYPE(MQK), ensure the following items are in effect:
1) Access authorization to these connections restricts access to the appropriate users as indicated in (b).
2) All access FAILUREs are logged.
d) If both of the items in (c) are true, there is NO FINDING.
e) If either item in (c) is untrue, this is a FINDING.
V-6962
False
ZWMQ0052
a) Refer to the following report produced by the ACF2 Data Collection:
- SENSITVE.RPT(MQCONN)
- ACF2CMDS.RPT(RESOURCE) – Alternate report
b) Review the following connection resources defined to TYPE(MQK) (i.e., MQCONN resource class):
Resource Authorized Users
ssid.BATCH TSO and batch job userids
ssid.CICS CICS region userids
ssid.IMS IMS region userids
ssid.CHIN Channel initiator userids
NOTE: ssid is the queue manager name (a.k.a., subsystem identifier).
c) For all connection resources defined to TYPE(MQK), ensure the following items are in effect:
1) Access authorization to these connections restricts access to the appropriate users as indicated in (b).
2) All access FAILUREs are logged.
d) If both of the items in (c) are true, there is NO FINDING.
e) If either item in (c) is untrue, this is a FINDING.
M
Information Assurance Officer
3595