| Ensure that the HASPINDX dataset identified in the INDEX parameter value of ISFPARMS options statement is restricted as described below. |
The HASPINDX data set is used by SDSF when building the SYSLOG panel. This data set contains information related to all SYSLOG jobs and data sets on the spool. Since SDSF dynamically allocates this data set, explicit user access authorization to this data set should not be required. Due to the potentially sensitive data in this data set, access authorization will be restricted.
READ access is restricted to the auditors.
UPDATE access is restricted to SDSF Started Tasks.
WRITE and/or greater access is restricted to systems programming personnel.
Note: If running z/OS V1R11 or above, with the use of a new JES logical log, the HASPINDX, may not exist and may make this vulnerability not applicable (N/A). However if used the HASPINDX dataset must be restricted.
Note: If running z/OS V1R11 systems or above and NOT using JES logical log, the HASPINDX data set must be protected.
Data sets to be protected will be:
The following commands are provided as a sample for implementing data set controls:
AD 'sys1.haspindx.**' UACC(NONE) OWNER(SYS1) AUDIT(FAILURES(READ))
PE ' sys1.haspindx.**' ID(syspaudt) ACC(A)
PE ' sys1.haspindx.**' ID(sdsf stc) ACC(U)
PE ' sys1.haspindx.**' ID(audtaudt) ACC(R)