Skip to content

IBM RACF assignment of the RACF OPERATIONS attribute to individual userids must be fully justified.

An XCCDF Rule

Description

<VulnDiscussion>This requirement is intended to cover both traditional interactive logons to information systems and general accesses to information systems that occur in other types of architectural configurations (e.g., service-oriented architectures).</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>

ID
SV-223714r604139_rule
Severity
Medium
References
Updated



Remediation - Manual Procedure

Review all USERIDs with the OPERATIONS attribute. Ensure documentation providing justification for access is maintained and filed with the ISSO, and that unjustified access is removed.

A sample command to remove the OPERATIONS attribute from a userid is shown here: 

ALU <userid> NOOPERATIONS