Check: TSS1030
zOS TSS STIG:
TSS1030
(in versions v6 r43 through v6 r30)
Title
Volume access greater than CREATE found in CA-Top Secret (TSS) database must be limited to authorized information technology personnel requiring access to perform their job duties. (Cat I impact)
Discussion
Access authorization to data sets is verified by examining both volume access and data set access authorization. If a user has been authorized for any volume access greater than CREATE, then TSS allows access to the volume without checking the data set authorizations. A user could potentially alter a data set that resides on a volume even though access has not been granted to that data set.
Check Content
a) Refer to the following report produced by the Data Set and Resource Data Collection: - SENSITVE.RPT(WHOHVOL) b) Determine whether or not access authorization greater than CREATE (e.g. CONTROL or ALL) has been granted for volumes. c) If access authorizations for volumes are within the requirements, there is NO FINDING. d) If access authorization for volumes exceeds the requirements without justification, this is a FINDING. NOTE: Domain level DASD Administrators who are responsible for the Domain level DASD/storage administration. Volume level access to those team members who are directly responsible and perform Domain level DASD/Storage administration may be granted access to all volumes via PRIVPGM controls.
Fix Text
The IAO will ensure that VOLUME access authorization greater than CREATE is not permitted unless authorized by the IAO. Review all access to VOLUMEs. Evaluate the impact of correcting the deficiency. Develop a plan of action and implement the required changes. *Noted Exception: Domain level DASD Administrators who are responsible for the Domain level DASD/storage administration. Volume level access to those team members who are directly responsible and perform Domain level DASD/Storage administration may be granted access to all volumes via PRIVPGM controls. Domain Level DASD/Storage administrators access should be granted VOL(*ALL*)ACC(ALL)ACTION(AUDIT)PRIVPGM(list of privileged programs)
Additional Identifiers
Rule ID: SV-247r3_rule
Vulnerability ID: V-247
Group Title: TSS1030
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000213 |
Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies. |
Controls
Number | Title |
---|---|
AC-3 |
Access Enforcement |