Check: ZFEP0012
zOS ACF2 STIG:
ZFEP0012
(in versions v6 r43 through v6 r30)
Title
Procedures are not in place to restrict access to FEP functions of the service subsystem from operator consoles (local and/or remote), and to restrict access to the diskette drive of the service subsystem. (Cat II impact)
Discussion
If components of the FEPs are not properly protected they can be stolen, damaged, or disturbed. Without adequate physical security, unauthorized users can access the control panel, the operator console, and the diskette drive of the service subsystem. Therefore, they can interfere with the normal operations of the FEPs. Improper control of FEP components could compromise network operations.
Check Content
a) Review site documentation to validate that procedures are in place to protect the FEP service subsystem and diskette drive: - Documents and procedures restricting access to the functions of the service subsystem from the control panel. - Documents and procedures restricting access to the functions of the service subsystem from the local and/or remote operator consoles (e.g., physical access, password control, key-lock switch of modems, etc.). - Documents and procedures restricting access to the diskette drive of the service subsystem. b) If a procedure is in place to restrict access to the functions of the service subsystem, there is NO FINDING. c) If a procedure is in place to restrict access to the functions of the service subsystem from operator consoles (local and/or remote), there is NO FINDING. d) If a procedure is in place to restrict access to the diskette drive of the service subsystem, there is NO FINDING. e) If no procedure exists for any of the above functions of the service subsystem and FEP resources, this is a FINDING.
Fix Text
Ensure that all hardware components of the FEPs are protected as decribed below and supporting documentation procedures exist for each item: 1. Documents and procedures restricting access to the hardware components of the FEPs. 2. Documents and procedures restricting access to the functions of the service subsystem from the control panel. 3. Documents and procedures restricting access to the functions of the service subsystem from the local and/or remote operator consoles (e.g., physical access, password control, key-lock switch of modems, etc.). 4. Documents and procedures restricting access to the diskette drive of the service subsystem.
Additional Identifiers
Rule ID: SV-7196r2_rule
Vulnerability ID: V-6901
Group Title: ZFEP0012
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000004 |
The organization develops procedures to facilitate the implementation of the access control policy and associated access controls. |
Controls
Number | Title |
---|---|
AC-1 |
Access Control Policy And Procedures |