Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-17469 | ZNETT036 | SV-28465r1_rule | Medium |
Description |
---|
Improperly defined security controls for the Product could result in the compromise of the network, operating system, and customer data. |
STIG | Date |
---|---|
z/OS NetView for TSS STIG | 2016-06-30 |
Check Text ( C-28788r1_chk ) |
---|
a) Refer to the following report produced by the TSS Data Collection: - TSSCMDS.RPT(FACLIST) - Preferred report containing all control option values in effect including default values - TSSCMDS.RPT(TSSPRMFL) - Alternate report containing only control option values explicitly coded at TSS startup b) If NETVIEW is properly defined in the Facility Matrix table, there is NO FINDING: c) If NETVIEW is improperly defined in the Facility Matrix table, this is a FINDING. |
Fix Text (F-25789r1_fix) |
---|
Define NETVIEW as a Facility to TOP SECRET in the Facility Matrix Table using the following example: **** NETVIEW * FACILITY(USERxx=NAME=NETVIEW) FACILITY(NETVIEW=MODE=FAIL) FACILITY(NETVIEW=PGM=DSI) FACILITY(NETVIEW=ACTIVE,SHRPRF,ASUBM,ABEND,MULTIUSER,NOXDEF) FACILITY(NETVIEW=LUMSG,STMSG,SIGN(M),INSTDATA,NORNDPW,AUTHINIT) FACILITY(NETVIEW=NOPROMPT,NOAUDIT,RES,WARNPW,NOTSOC,LCFTRANS,IJU) FACILITY(NETVIEW=MSGLC,NOTRACE,NOEODINIT,NODORMPW,NONPWR) FACILITY(NETVIEW=LOG(INIT,SMF,MSG,SEC9)) FACILITY(NETVIEW=DOWN=GLOBAL,LOCKTIME=00,DEFACID(*NONE*)) |