z/OS UNIX SUPERUSER resource must be protected in accordance with guidelines.

From z/OS ACF2 STIG

Part of ZUSS0023

Associated with IA controls: DCCS-1, ECCD-2, DCCS-2, ECCD-1

Associated with: CCI-000213 CCI-001764

SV-7275r3_rule z/OS UNIX SUPERUSER resource must be protected in accordance with guidelines.

Vulnerability discussion

z/OS UNIX ACP-defined resources consist of sensitive capabilities including SUPERUSER, daemon, and numerous file manipulation privileges. Missing or inaccurate protection of these resources could allow a user to access sensitive data, modify or delete data and operating system controls, or issue commands that could negatively impact system availability.

Check content

a) Refer to the following report produced by the ACF2 Data Collection and Data Set and Resource Data Collection: - SENSITVE.RPT(UNIXPRIV) - ACF2CMDS.RPT(RESOURCE) – Alternate report Automated Analysis Refer to the following report produced by the Data Set and Resource Data Collection: - PDI(ZUSS0023) b) Review the following items for the UNIXPRIV resource class, TYPE(UNI): 1) The ACF2 rules for the SUPERUSER resource specify a default access of NONE. 2) There are no ACF2 rules that allow access to the SUPERUSER resource. 3) There is no ACF2 rule for CHOWN.UNRESTRICTED defined. 4) The ACF2 rules for each of the SUPERUSER resources listed in the UNIXPRIV CLASS RESOURCES Table in the z/OS STIG Addendum, specify a default access of NONE. 5) The ACF2 rules for each of the SUPERUSER resources listed in the UNIXPRIV CLASS RESOURCES Table in the z/OS STIG Addendum, restrict access to appropriate system tasks or systems programming personnel. c) If any item in (b) is untrue, this is a FINDING. d) If all items in (b) are true, this is NOT A FINDING.

Fix text

The IAO will ensure that all SUPERUSER resources for the UNIXPRIV resource class are restricted to appropriate system tasks and/or system programming personnel. The ACF2 rules for the SUPERUSER resource specify a default access of NONE. There are no ACF2 rules that allow access to the SUPERUSER resource. There is no ACF2 rule for CHOWN.UNRESTRICTED defined. The ACF2 rules for each of the SUPERUSER resources listed in the UNIXPRIV CLASS RESOURCES Table in the z/OS STIG Addendum, specify a default access of NONE. The ACF2 rules for each of the SUPERUSER resources listed in the UNIXPRIV CLASS RESOURCES Table in the z/OS STIG Addendum, restrict access to appropriate system tasks or systems programming personnel. Example: SET R(UNI) $KEY(SUPERUSER) TYPE(UNI) $MEMBER(SUPRUSER) FILESYS UID(syspaudt LOG FILESYS.CHOWN UID(syspaudt) LOG FILESYS.MOUNT UID(syspaudt) LOG FILESYS.PFSCTL UID(syspaudt) LOG FILESYS.VREGISTER UID(syspaudt) LOG IPC.RMID UID(syspaudt) LOG PROCESS.GETPSENT UID(syspaudt) LOG PROCESS.KILL UID(syspaudt) LOG PROCESS.PTRACE UID(syspaudt) LOG SETPRIORITY UID(syspaudt) LOG - UID(*) PREVENT

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer