BMC CONTROL-M Started task(s) must be properly defined to the Started Task Table ACID for Top Secret.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-224575ZCTMT032SV-224575r1145936_ruleCCI-000764medium
Description
Access to product resources should be restricted to only those individuals responsible for the application connectivity and who have a requirement to access these resources. Improper control of product resources could potentially compromise the operating system, ACP, and customer data.
STIGDate
zOS BMC CONTROL-M for TSS Security Technical Implementation Guide2025-09-28

Details

Check Text (C-224575r1145936_chk)

Refer to the following report produced by the TSS Data Collection: - TSSCMDS.RPT(#STC). Automated Analysis Refer to the following report produced by the TSS Data Collection: - PDI(ZCTM0032). If the BMC CONTROL-M started task(s) is (are) defined in the TSS STC record, this is not a finding.

Fix Text (F-26246r1145935_fix)

The BMC CONTROL-M systems programmer and the ISSO will ensure that a product's started task(s) is (are) properly identified and/or defined to the system ACP. A unique ACID must be assigned for the BMC CONTROL-M started task(s) through a corresponding STC table entry. The following sample set of commands is shown here as a guideline: TSS ADD(STC) PROCNAME(CONTOLM) ACID(CONTROLM)