UCF STIG Viewer Logo

ACIDs granted the CONSOLE attribute must be justified.


Overview

Finding ID Version Rule ID IA Controls Severity
V-237 TSS0890 SV-237r3_rule DCCS-1 DCCS-2 High
Description
CONSOLE attribute grants the ability to modify SECURITY PRODUCT CONTROL options online, including capability to change many critical Control Options. Restricting this facility prevents operators or other personnel from executing sensitive started tasks or changing security control options without proper authorization.
STIG Date
z/OS TSS STIG 2019-12-12

Details

Check Text ( C-572r1_chk )
Refer to the following report produced by the TSS Data Collection:

- TSSPRIV.RPT

Automated Analysis
Refer to the following report produced by the TSS Data Collection:

- PDI(TSS0890)

Ensure that ACIDs with CONSOLE authority are limited to authorized SCA security administrators and the system programmers that maintain the CA-TSS software product only.
Fix Text (F-18185r1_fix)
Review all ACIDs with the CONSOLE attribute. Ensure access is limited to authorized SCA security administrators only. Evaluate the impact of correcting the deficiency. Develop a plan of action and implement the changes. Ensure documentation providing justification for access is maintained and filed with the IAO.