Check: ZUSS0023
zOS RACF STIG:
ZUSS0023
(in versions v6 r43 through v6 r30)
Title
z/OS UNIX SUPERUSER resource must be protected in accordance with guidelines. (Cat I impact)
Discussion
z/OS UNIX ACP-defined resources consist of sensitive capabilities including SUPERUSER, daemon, and numerous file manipulation privileges. Missing or inaccurate protection of these resources could allow a user to access sensitive data, modify or delete data and operating system controls, or issue commands that could negatively impact system availability.
Check Content
a) Refer to the following report produced by the Data Set and Resource Data Collection: - SENSITVE.RPT(UNIXPRIV) Automated Analysis Refer to the following report produced by the Data Set and Resource Data Collection: - PDI(ZUSS0023) b) Review the following items for the UNIXPRIV resource class: 1) The RACF rules for the SUPERUSER resource specify a default access of NONE. 2) There are no RACF rules that allow access to the SUPERUSER resource. 3) There is no RACF rule for CHOWN.UNRESTRICTED defined. 4) The RACF rules for each of the SUPERUSER resources listed in the UNIXPRIV CLASS RESOURCES Table in the z/OS STIG Addendum, specify a default access of NONE. 5) The RACF rules for each of the SUPERUSER resources listed in the UNIXPRIV CLASS RESOURCES Table in the z/OS STIG Addendum, restrict access to appropriate system tasks or systems programming personnel. c) If any item in (b) is untrue, this is a FINDING. d) If all items in (b) are true, this is NOT A FINDING.
Fix Text
Ensure that all SUPERUSER resources for the UNIXPRIV resource class are restricted to appropriate system tasks and/or system programming personnel. 1) The RACF rules for the SUPERUSER resource specify a default access of NONE. 2) There are no RACF rules that allow access to the SUPERUSER resource. 3) There is no RACF rule for CHOWN.UNRESTRICTED defined. 4) The RACF rules for each of the SUPERUSER resources listed in the UNIXPRIV CLASS RESOURCES Table in the z/OS STIG Addendum, specify a default access of NONE. 5) The RACF rules for each of the SUPERUSER resources listed in the UNIXPRIV CLASS RESOURCES Table in the z/OS STIG Addendum, restrict access to appropriate system tasks or systems programming personnel. Sample Commands: RDEF UNIXPRIV SUPERUSER.** UACC(NONE) OWNER(ADMIN) DATA('REFERENCE ZUSS0023') AUDIT(ALL(READ)) /* do not permit any users/groups to this resource */ SR CLASS(UNIXPRIV) MASK(CHOWN.UNRESTRICTED) /* delete if found */ PE SUPERUSER.FILESYS.** CL(UNIXPRIV) ID(<SYSPAUDT>) /* where SUPERUSER.FILESYS.** represents one of the resources listed in the UNIXPRIV CLASS RESOURCES table in the Addendum */
Additional Identifiers
Rule ID: SV-19748r3_rule
Vulnerability ID: V-6972
Group Title: ZUSS0023
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000213 |
The information system enforces approved authorizations for logical access to information and system resources in accordance with applicable access control policies. |
CCI-001764 |
The information system prevents program execution in accordance with organization-defined policies regarding software program usage and restrictions, and/or rules authorizing the terms and conditions of software program usage. |