Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-237 | TSS0890 | SV-237r3_rule | DCCS-1 DCCS-2 | High |
Description |
---|
CONSOLE attribute grants the ability to modify SECURITY PRODUCT CONTROL options online, including capability to change many critical Control Options. Restricting this facility prevents operators or other personnel from executing sensitive started tasks or changing security control options without proper authorization. |
STIG | Date |
---|---|
z/OS TSS STIG | 2018-10-04 |
Check Text ( C-572r1_chk ) |
---|
Refer to the following report produced by the TSS Data Collection: - TSSPRIV.RPT Automated Analysis Refer to the following report produced by the TSS Data Collection: - PDI(TSS0890) Ensure that ACIDs with CONSOLE authority are limited to authorized SCA security administrators and the system programmers that maintain the CA-TSS software product only. |
Fix Text (F-18185r1_fix) |
---|
Review all ACIDs with the CONSOLE attribute. Ensure access is limited to authorized SCA security administrators only. Evaluate the impact of correcting the deficiency. Develop a plan of action and implement the changes. Ensure documentation providing justification for access is maintained and filed with the IAO. |