Check: ZIOAT036
z/OS BMC IOA for TSS STIG:
ZIOAT036
(in versions v6 r8 through v6 r6)
Title
BMC IOA is not properly defined to the Facility Matrix Table for Top Secret. (Cat II impact)
Discussion
Improperly defined security controls for BMC IOA could result in the compromise of the network, operating system, and customer data.
Check Content
Refer to the following report produced by the TSS Data Collection: - TSSCMDS.RPT(FACLIST) - Preferred report containing all control option values in effect including default values - TSSCMDS.RPT(TSSPRMFL) - Alternate report containing only control option values explicitly coded at TSS startup Ensure the BMC IOA Facility Matrix table is defined as follows: FAC(USERxx=NAME=IOA,PGM=IOA,ID=nn,ACTIVE,SHRPRF,ASUBM) FAC(IOA=NOABEND,MULTIUSER,NOXDEF,SIGN(S),RES,LUMSG) FAC(IOA=STMSG,WARNPW,NORNDPW,NOAUDIT,NOTSOC,MODE=FAIL) FAC(IOA=LOG(SMF,INIT,MSG,SEC9),UIDACID=8,LOCKTIME=000)
Fix Text
The BMC IOA system programmer and the IAO will ensure that the TOP SECRET Facility Matrix Table is proper defined using the following example: IOA: FACILITY(USERxx=NAME=IOA,PGM=IOA,ID=nn,ACTIVE,SHRPRF) FACILITY(IOA=ASUBM,NOABEND,MULTIUSER,NOXDEF) FACILITY(IOA=LUMSG,STMSG,SIGN(S),NORNDPW) FACILITY(IOA=NOAUDIT,RES,WARNPW,NOTSOC) FACILITY(IOA=MODE=FAIL,LOG(SMF,INIT,MSG,SEC9)) FACILITY(IOA=UIDACID=8,LOCKTIME=000)
Additional Identifiers
Rule ID: SV-224605r518955_rule
Vulnerability ID: V-224605
Group Title: SRG-OS-000104
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000764 |
The information system uniquely identifies and authenticates organizational users (or processes acting on behalf of organizational users). |
Controls
Number | Title |
---|---|
IA-2 |
Identification And Authentication (Organizational Users) |