Check: ACF0250
zOS ACF2 STIG:
ACF0250
(in versions v6 r43 through v6 r37)
Title
The APPLDEF GSO record if used must have supporting documentation indicating the reason it was used. (Cat III impact)
Discussion
The system-wide options control the default settings for determining how the ACP will function when handling requests for access to the operating system environment, ACP, and customer data. The ACP provides the ability to set a number of these fields at the subsystem level. If no setting is found, the system-wide defaults will be used. The improper setting of any one of these fields, individually or in combination with another, can compromise the security of the processing environment. In addition, failure to establish standardized settings for the ACP control options introduces the possibility of exposure during a migration process or contingency plan activation.
Check Content
a) Refer to the following report produced by the ACF2 Data Collection Checklist: - ACF2CMDS.RPT(ACFGSO) Automated Analysis requires Additional Analysis. Automated Analysis Refer to the following report produced by the ACF2 Data Collection Checklist: - PDI(ACF0250) b) If the GSO APPLDEF record does not exist, there is NO FINDING. c) If the GSO APPLDEF record does exist and no supporting documentation is available, this is a FINDING.
Fix Text
The IAO will ensure that the APPLDEF GSO record if used has supporting documentation indicating the reason it was used. The APPLDEF record is optional.
Additional Identifiers
Rule ID: SV-130r3_rule
Vulnerability ID: V-130
Group Title: ACF0250
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
CCI-000368 |
The organization documents any deviations from the established configuration settings for organization-defined information system components based on organization-defined operational requirements. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |