Check: TSS0-FT-000050
IBM z/OS TSS STIG:
TSS0-FT-000050
(in versions v8 r13 through v7 r1)
Title
IBM z/OS FTP Control cards must be properly stored in a secure PDS file. (Cat II impact)
Discussion
Configuration settings are the set of parameters that can be changed in hardware, software, or firmware components of the system that affect the security posture and/or functionality of the system. Security-related parameters are those parameters impacting the security state of the system, including the parameters required to satisfy other security control requirements. Security-related parameters include, for example: registry settings; account, file, directory permission settings; and settings for functions, ports, protocols, services, and remote connections.
Check Content
Ask the System administrator fora list(s) of the locations for all FTP Control cards within a given application/AIS, ensuring no FTP control cards are within in-stream JCL, JCL libraries or any open access data sets. If access to PDS files where FTP Control cards are stored are not restricted to appropriate personnel this is a finding.
Fix Text
Make sure that the FTP control Cards for each FTP are stored in a secure PDS and that they are not placed in the JCL libraries or in the in-stream JCL for each FTP.
Additional Identifiers
Rule ID: SV-223977r877818_rule
Vulnerability ID: V-223977
Group Title: SRG-OS-000480-GPOS-00227
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000202 |
The organization ensures unencrypted static authenticators are not embedded in access scripts. |
CCI-000366 |
The organization implements the security configuration settings. |