Check: TSS0890
zOS TSS STIG:
TSS0890
(in versions v6 r43 through v6 r30)
Title
ACIDs granted the CONSOLE attribute must be justified. (Cat I impact)
Discussion
CONSOLE attribute grants the ability to modify SECURITY PRODUCT CONTROL options online, including capability to change many critical Control Options. Restricting this facility prevents operators or other personnel from executing sensitive started tasks or changing security control options without proper authorization.
Check Content
Refer to the following report produced by the TSS Data Collection: - TSSPRIV.RPT Automated Analysis Refer to the following report produced by the TSS Data Collection: - PDI(TSS0890) Ensure that ACIDs with CONSOLE authority are limited to authorized SCA security administrators and the system programmers that maintain the CA-TSS software product only.
Fix Text
Review all ACIDs with the CONSOLE attribute. Ensure access is limited to authorized SCA security administrators only. Evaluate the impact of correcting the deficiency. Develop a plan of action and implement the changes. Ensure documentation providing justification for access is maintained and filed with the IAO.
Additional Identifiers
Rule ID: SV-237r3_rule
Vulnerability ID: V-237
Group Title: TSS0890
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000035 |
Provide the capability for privileged administrators to configure the organization-defined security or privacy policy filters to support different security or privacy policies. |
Controls
Number | Title |
---|---|
AC-4(11) |
Configuration of Security Policy Filters |