Skip to content

IBM z/OS UNIX groups must be defined with a unique GID.

An XCCDF Rule

Description

To assure accountability and prevent unauthenticated access, organizational users must be identified and authenticated to prevent potential misuse and compromise of the system. RACF userid groups, and started tasks that use z/OS UNIX facilities are defined to an ACP with attributes including UID and GID. If these attributes are not correctly defined, data access or command privilege controls could be compromised.

ID
SV-223857r958482_rule
Version
RACF-US-000200
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Define each UNIX group with a unique GID.

Define the OMVSGRP group and/or the STCOMVS group to the security database with a unique GID in the range of 1-99.

OMVSGRP is the name suggested by IBM for all the required userids. STCOMVS is the standard name used at some sites for the userids that are associated with z/OS UNIX started tasks and daemons. These groups can be combined at the site's discretion.