Check: ZSMSR008
zOS RACF STIG:
ZSMSR008
(in versions v6 r43 through v6 r30)
Title
DFSMS-related RACF classes are not active. (Cat II impact)
Discussion
DFSMS provides data, storage, program, and device management functions for the operating system. Some DFSMS storage administration functions allow a user to obtain a privileged status and effectively bypass all ACP data set and volume controls. Failure to properly protect DFSMS resources may result in unauthorized access. This exposure could compromise the availability and integrity of the operating system environment, system services, and customer data.
Check Content
CLASSACT Resources a) Refer to the following report produced by the RACF Data Collection: - RACFCMDS.RPT(SETROPTS) b) ACTIVE CLASSES lists the MGMTCLAS, STORCLAS, PROGRAM, and FACILITY resources classes. c) RACLIST CLASSES lists the MGMTCLAS and STORCLAS resource classes. d) If (b) and (c) are true, there is NO FINDING. e) If (b) or (c) is not true, this is a FINDING.
Fix Text
CLASSACT Resources ACTIVE CLASSES lists the MGMTCLAS, STORCLAS, PROGRAM, and FACILITY resources classes. The classes can be activated with the command: SETR CLASSACT(MGMTCLAS STORCLAS PROGRAM FACILITY) RACLIST CLASSES lists the MGMTCLAS and STORCLAS resource classes. The classes can be RACLISTED with the command: SETR RACL(MGMTCLAS STORCLAS)
Additional Identifiers
Rule ID: SV-7244r2_rule
Vulnerability ID: V-6943
Group Title: ZSMSR008
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000213 |
The information system enforces approved authorizations for logical access to information and system resources in accordance with applicable access control policies. |
Controls
Number | Title |
---|---|
AC-3 |
Access Enforcement |