UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

z/OS UNIX SUPERUSER resource must be protected in accordance with guidelines.


Overview

Finding ID Version Rule ID IA Controls Severity
V-6972 ZUSS0023 SV-7275r3_rule DCCS-1 DCCS-2 ECCD-1 ECCD-2 High
Description
z/OS UNIX ACP-defined resources consist of sensitive capabilities including SUPERUSER, daemon, and numerous file manipulation privileges. Missing or inaccurate protection of these resources could allow a user to access sensitive data, modify or delete data and operating system controls, or issue commands that could negatively impact system availability.
STIG Date
z/OS ACF2 STIG 2018-12-20

Details

Check Text ( C-20755r1_chk )
a) Refer to the following report produced by the ACF2 Data Collection and Data Set and Resource Data Collection:

- SENSITVE.RPT(UNIXPRIV)
- ACF2CMDS.RPT(RESOURCE) – Alternate report

Automated Analysis
Refer to the following report produced by the Data Set and Resource Data Collection:

- PDI(ZUSS0023)

b) Review the following items for the UNIXPRIV resource class, TYPE(UNI):

1) The ACF2 rules for the SUPERUSER resource specify a default access of NONE.
2) There are no ACF2 rules that allow access to the SUPERUSER resource.
3) There is no ACF2 rule for CHOWN.UNRESTRICTED defined.
4) The ACF2 rules for each of the SUPERUSER resources listed in the UNIXPRIV CLASS RESOURCES Table in the z/OS STIG Addendum, specify a default access of NONE.
5) The ACF2 rules for each of the SUPERUSER resources listed in the UNIXPRIV CLASS RESOURCES Table in the z/OS STIG Addendum, restrict access to appropriate system tasks or systems programming personnel.

c) If any item in (b) is untrue, this is a FINDING.

d) If all items in (b) are true, this is NOT A FINDING.
Fix Text (F-19109r1_fix)
The IAO will ensure that all SUPERUSER resources for the UNIXPRIV resource class are restricted to appropriate system tasks and/or system programming personnel.

The ACF2 rules for the SUPERUSER resource specify a default access of NONE.

There are no ACF2 rules that allow access to the SUPERUSER resource.

There is no ACF2 rule for CHOWN.UNRESTRICTED defined.

The ACF2 rules for each of the SUPERUSER resources listed in the UNIXPRIV CLASS RESOURCES Table in the z/OS STIG Addendum, specify a default access of NONE.

The ACF2 rules for each of the SUPERUSER resources listed in the UNIXPRIV CLASS RESOURCES Table in the z/OS STIG Addendum, restrict access to appropriate system tasks or systems programming personnel.

Example:

SET R(UNI)
$KEY(SUPERUSER) TYPE(UNI)
$MEMBER(SUPRUSER)
FILESYS UID(syspaudt LOG
FILESYS.CHOWN UID(syspaudt) LOG
FILESYS.MOUNT UID(syspaudt) LOG
FILESYS.PFSCTL UID(syspaudt) LOG
FILESYS.VREGISTER UID(syspaudt) LOG
IPC.RMID UID(syspaudt) LOG
PROCESS.GETPSENT UID(syspaudt) LOG
PROCESS.KILL UID(syspaudt) LOG
PROCESS.PTRACE UID(syspaudt) LOG
SETPRIORITY UID(syspaudt) LOG
- UID(*) PREVENT