The LOGONIDs specified In GSO MAINT records will have the JOB and MAINT attributes specified In the associated LOGONID record.

From z/OS ACF2 STIG

Part of ACF0680

Associated with IA controls: DCCS-1, DCCS-2

Associated with: CCI-002145 CCI-002883

SV-2r3_rule The LOGONIDs specified In GSO MAINT records will have the JOB and MAINT attributes specified In the associated LOGONID record.

Vulnerability discussion

If there is a LOGONID intended for maintenance purposes that does not have the MAINT and JOB attributes specified, then it cannot function as intended. This could result in the inability to perform critical system maintenance tasks.

Check content

Refer to the following reports produced by the ACF2 Data Collection: - ACF2CMDS.RPT(ACFGSO) - ACF2CMDS.RPT(ATTMAINT) Automated Analysis Refer to the following report produced by the ACF2 Data Collection Checklist: - PDI(ACF0680) For each logonid record associated to the LID entry in all GSO MAINT records specify the following, this is not a finding. ___ The JOB and MAINT attributes are specified.

Fix text

The IAO will ensure that logonids assigned to production maintenance tasks have the JOB and MAINT field settings in addition to the default LID field settings. Production maintenance tasks manage the backups and restoration of data for the Continuity of Operations Plan (COOP) and media maintenance. Logonids assigned to production maintenance tasks will have the following field settings in addition to the default LID field settings: JOB MAINT Example: SET LID CHANGE DFSMSHSM JOB MAINT

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer