Check: TSS0-OS-000330
IBM z/OS TSS STIG:
TSS0-OS-000330
(in versions v8 r11 through v7 r1)
Title
IBM z/OS must employ a session manager to manage retaining a users session lock until that user reestablishes access using established identification and authentication procedures. (Cat II impact)
Discussion
A session lock is a temporary action taken when a user stops work and moves away from the immediate physical vicinity of the information system but does not want to log out because of the temporary nature of the absence. The session lock is implemented at the point where session activity can be determined. Regardless of where the session lock is determined and implemented, once invoked, the session lock will remain in place until the user re-authenticates. No other activity aside from re-authentication will unlock the system.
Check Content
Verify the any Session Manager in use retains a user's session lock until that user reestablishes access using established identification and authentication procedures. If it does not, this is a finding.
Fix Text
Configure any Session Manager in use to retain a user's session lock until that user reestablishes access using established identification and authentication procedures.
Additional Identifiers
Rule ID: SV-224029r877867_rule
Vulnerability ID: V-224029
Group Title: SRG-OS-000480-GPOS-00227
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |