CA VTAPE Started task(s) must be properly defined to the Started Task Table ACID for Top Secret.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-224635ZVTAT032SV-224635r1146181_ruleCCI-000764medium
Description
Access to product resources should be restricted to only those individuals responsible for the application connectivity and who have a requirement to access these resources. Improper control of product resources could potentially compromise the operating system, ACP, and customer data.
STIGDate
z/OS CA VTAPE for TSS Security Technical Implementation Guide2025-09-28

Details

Check Text (C-224635r1146181_chk)

Refer to the following report produced by the TSS Data Collection: - TSSCMDS.RPT(#STC). Automated Analysis Refer to the following report produced by the TSS Data Collection: - PDI(ZVTA0032). If the CA VTAPE started task(s) is (are) defined in the TSS STC record, this is not a finding.

Fix Text (F-26306r1146180_fix)

The CA VTAPE systems programmer and the ISSO will ensure that a product's started task(s) is (are) properly identified and/or defined to the system ACP. A unique ACID must be assigned for the CA VTAPE started task(s) through a corresponding STC table entry. The following sample set of commands is shown here as a guideline: TSS ADD(STC) PROCNAME(CVTS) ACID(CVTS) TSS ADD(STC) PROCNAME(CVTSAS) ACID(CVTSAS)