There are LOGONIDs associated with started tasks that have the MUSASS requirement but do not have both the MUSASS and NO-SMC specified in corresponding LOGONID records.

From z/OS ACF2 STIG

Part of ACF0610

Associated with IA controls: DCCS-1, DCCS-2

SV-162r1_rule There are LOGONIDs associated with started tasks that have the MUSASS requirement but do not have both the MUSASS and NO-SMC specified in corresponding LOGONID records.

Vulnerability discussion

If the LOGONID does not have the MUSASS attribute specified, there is no individual accountability within the associated address space.If NO-SMC is not specified the potential for VSAM data set corruption exists.

Check content

a) Refer to the following reports produced by the ACF2 Data Collection: - ACF2CMDS.RPT(ATTSTC) - ACF2CMDS.RPT(ATTMUASS) Automated Analysis Refer to the following report produced by the ACF2 Data Collection Checklist: - PDI(ACF0610) b) Identify the started tasks that have a Multi-User Single Address Space System (MUSASS) requirement. c) If every logonid associated with a started task that has the MUSASS requirement has the MUSASS and NO-SMC attributes, there is NO FINDING. d) If any logonid associated with a started task that has the MUSASS requirement does not have the MUSASS and NO-SMC attributes, this is a FINDING.

Fix text

The IAO will ensure that if the STC is a Multi User Single Address Space System (MUSASS), the STC logonid has the MUSASS and NO-SMC attributes. If the started task (STC) is a Multi User Single Address Space System (MUSASS), the STC logonid will also have the following attributes: MUSASS NO-SMC Example: SET LID INSERT logonid STC MUSASS NO-SMC

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer