BMC IOA Started task(s) must be properly defined to the Started Task Table ACID for Top Secret.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-224604ZIOAT032SV-224604r1146020_ruleCCI-000764medium
Description
Access to product resources should be restricted to only those individuals responsible for the application connectivity and who have a requirement to access these resources. Improper control of product resources could potentially compromise the operating system, ACP, and customer data.
STIGDate
z/OS BMC IOA for TSS Security Technical Implementation Guide2025-09-28

Details

Check Text (C-224604r1146020_chk)

Refer to the following report produced by the TSS Data Collection: - TSSCMDS.RPT(#STC). Automated Analysis Refer to the following report produced by the TSS Data Collection: - PDI(ZIOA0032). If the BMC IOA started task(s) is (are) defined in the TSS STC record, this is not a finding.

Fix Text (F-26275r1146019_fix)

The BMC IOA systems programmer and the ISSO will ensure that a product's started task(s) is (are) properly identified and/or defined to the system ACP. A unique ACID must be assigned for the BMC IOA started task(s) through a corresponding STC table entry. The following sample set of commands is shown here as a guideline: TSS ADD(STC) PROCNAME(IOAGATE) ACID(IOAGATE)