V-224496
z/OS IBM CICS Transaction Server for RACF Security Technical Implementation Guide
Title
CICS default logonid(s) must be defined and/or controlled in accordance with the security requirements.
Description
<VulnDiscussion>CICS is a transaction-processing product that provides programmers with the facilities to develop interactive applications. An improperly defined or controlled CICS default userid may provide an exposure and vulnerability within the CICS environment. This could result in the compromise of the confidentiality, integrity, and availability of the CICS region, applications, and customer data.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documenta...
Fix Text (Documentation Requirement)
Ensure the following items are in effect for the CICS default userid (i.e., DFLTUSER=default userid). If the following guidance is true, this is not a finding. Not granted the RACF OPERATIONS attribute. Issue a RACF LU (Listuser) command on the CICS default userid. The OPERATIONS attribute can be removed via the RACF command ALU <cicsdefaultuser> NOOPERATIONS No access to interactive on-line facilities (e.g., TSO) other than CICS. Use the RACF ALU (Altuser) command to remove attributes such as TSO. Example: ALU <cicsdefaultuser> NOTSO TIMEOUT parameter in the CICS segment is set to 15 minutes. A system's default time for terminal lockout or session termination may be lengthened to 30 minutes at the discretion of the ISSM. The ISSM will maintain the documentation for each system with...