Rule ID
SV-224605r1146023_rule
Version
V7R2
CCIs
Improperly defined security controls for BMC IOA could result in the compromise of the network, operating system, and customer data.
Refer to the following reports produced by the TSS Data Collection: - TSSCMDS.RPT(FACLIST) - Preferred report containing all control option values in effect including default values. - TSSCMDS.RPT(TSSPRMFL) - Alternate report containing only control option values explicitly coded at TSS startup. If the BMC IOA Facility Matrix table is defined as stated below, this is not a finding. FAC(USERxx=NAME=IOA,PGM=IOA,ID=nn,ACTIVE,SHRPRF,ASUBM) FAC(IOA=NOABEND,MULTIUSER,NOXDEF,SIGN(S),RES,LUMSG) FAC(IOA=STMSG,WARNPW,NORNDPW,NOAUDIT,NOTSOC,MODE=FAIL) FAC(IOA=LOG(SMF,INIT,MSG,SEC9),UIDACID=8,LOCKTIME=000)
The BMC IOA systems programmer and the ISSO will ensure that the TOP SECRET Facility Matrix Table is proper defined using the following example: IOA: FACILITY(USERxx=NAME=IOA,PGM=IOA,ID=nn,ACTIVE,SHRPRF) FACILITY(IOA=ASUBM,NOABEND,MULTIUSER,NOXDEF) FACILITY(IOA=LUMSG,STMSG,SIGN(S),NORNDPW) FACILITY(IOA=NOAUDIT,RES,WARNPW,NOTSOC) FACILITY(IOA=MODE=FAIL,LOG(SMF,INIT,MSG,SEC9)) FACILITY(IOA=UIDACID=8,LOCKTIME=000)