STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← Back to z/OS CA 1 Tape Management for TSS Security Technical Implementation Guide

V-224637

CAT II (Medium)

CA 1 Tape Management user exits, when in use, must be reviewed and/or approved.

Rule ID

SV-224637r1145803_rule

STIG

z/OS CA 1 Tape Management for TSS Security Technical Implementation Guide

Version

V7R2

CCIs

CCI-001744

Discussion

CA-1 Tape Management user exits, TMSUXnA and TMSUXnS, provide the capability to bypass or modify existing ACP controls. A review and evaluation of exit code must be performed to ensure that the integrity of the CA-1 processing environment is kept intact. Unauthorized usage of these exits may compromise the confidentiality and integrity of customer data.

Check Content

Refer to the following report produced by the z/OS Data Collection:

- CA1RPT(TMSCKLVL).

Determine if CA 1 user exits, TMSUXnA and TMSUXnS (for r11.5 and below) or TMSXITA and TMSXITS (for r12.0 and above) are active.

If both CA 1 user exits are not found, this is not a finding.

If one or both user exits are installed and the following requirements are true, this is not a finding:

The usage and function of the user exit(s) is fully documented.
The use of the user exit(s) is approved.
All associated documentation is on file with the ISSO.

Fix Text

Ensure that the site ISSO has reviewed, evaluated, and approved the usage of CA 1 user exits, TMSUXnA and TMSUXnS (for r11.5 and below) or TMSXITA and TMSXITS (for r12.0 and above). If one or both user exits are installed and the following requirements will be followed:

The usage and function of the user exit(s) is fully documented.

The use of the user exit(s) is approved.

All associated documentation is on file with the ISSO.