Skip to content

CICS startup JCL statement is not specified in accordance with the proper security requirements.

An XCCDF Rule

Description

<VulnDiscussion>The CICS SIT is used to define system operation and configuration parameters of a CICS system. Several of these parameters control the security within a CICS region. Failure to code the appropriate values could result in unexpected operations and degraded security. This exposure may result in unauthorized access impacting the confidentiality, integrity, and availability of the CICS region, applications, and customer data.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>

ID
SV-224310r520252_rule
Severity
Medium
References
Updated



Remediation - Manual Procedure

The IAO will ensure that each CICS region procedure has the ACF2/CICS parameter dataset specified.

Ensure every CICS region on the system has the ACF2PARM DD statement in the CICS startup JCL.

View the started task proc for each CICS region in SYS3.PROCLIB using ISPF.