STIGQter STIGQter: STIG Summary: z/OS IBM CICS Transaction Server for RACF STIG Version: 6 Release: 6 Benchmark Date: 24 Apr 2020:

CICS region logonid(s) must be defined and/or controlled in accordance with the security requirements.

DISA Rule

SV-7532r4_rule

Vulnerability Number

V-44

Group Title

ZCIC0040

Rule Version

ZCIC0040

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Review all CICS region, default, and end-user userids to ensure they are defined and controlled as required.

Ensure that the following is defined for each CICS region:

1) A unique userid is defined.

Use the RACF Adduser command to accomplish this. A sample command is provided here:

AU <cicsregionid> NAME('STC, CICS Region') DFLTGRP(STC) OWNER(STC)

2) Defined to the STARTED resource class.

Use the RACF RDEFINE command. A sample is provided here:

RDEF STARTED <cicsprocname>.** UACC(NONE) OWNER(ADMIN) DATA('USED TO MAP <cicsprocname> TO A VALID RACF USERID') STDATA(USER(=MEMBER) GROUP(STC) TRACE(YES))

Check Contents

a) Refer to the following report produced by the z/OS Data Collection:

- EXAM.RPT(CICSPROC)

Refer to the following reports produced by the RACF Data Collection:

- RACFCMDS.RPT(LISTUSER)
- DSMON.RPT(RACCDT)

Refer to the CICS Systems Programmer Worksheets filled out from previous vulnerability ZCIC0010.

b) Ensure that the following is defined for each CICS region:

1) A unique userid is defined.
2) Defined to the STARTED resource class.

c) If (b) is true, this is not a finding.

d) If (b) is untrue, this is a finding.

Vulnerability Number

V-44

Documentable

False

Rule Version

ZCIC0040

Severity Override Guidance

a) Refer to the following report produced by the z/OS Data Collection:

- EXAM.RPT(CICSPROC)

Refer to the following reports produced by the RACF Data Collection:

- RACFCMDS.RPT(LISTUSER)
- DSMON.RPT(RACCDT)

Refer to the CICS Systems Programmer Worksheets filled out from previous vulnerability ZCIC0010.

b) Ensure that the following is defined for each CICS region:

1) A unique userid is defined.
2) Defined to the STARTED resource class.

c) If (b) is true, this is not a finding.

d) If (b) is untrue, this is a finding.

Check Content Reference

M

Responsibility

Information Assurance Officer

Target Key

197

Comments