IBM Support

OA50640: PCI-DSS RULE 7.1.1 REPORTS GENERIC GLOBAL ACCESS CHECKING TABLE MEMBER ENTRIES AS NON-COMPLIANT

A fix is available

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • PCI-DSS rule 7.1.1 reports generic Global Access Checking table
    member entries as non-compliant but the description states:
    "RACF discrete GENERAL profiles with ALTER authority"
    

Local fix

  • n/a
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED: Users of zSecure Audit exploiting the        *
    *                 PCI-DSS compliance rule set 7.1.1.           *
    ****************************************************************
    * PROBLEM DESCRIPTION: The zSecure Audit PCI-DSS compliance    *
    *                      rule set 7.1.1 reports the generic      *
    *                      global access checking table members as *
    *                      non-compliant.                          *
    ****************************************************************
    * RECOMMENDATION: Apply the PTF propvided.                     *
    ****************************************************************
    The PCI-DSS compliance rule set 7.1.1 (Access rights for
    for privileged user IDs must be restricted to least privileges
    to perform job responsibilities) reports generic global access
    checking table members as non-compliant with a confusing
    description that states "RACF discrete GENERAL profiles with
    ALTER authority".
    

Problem conclusion

  • zSecure Audit has been modified so that the PCI-DSS compliance
    rule set 7.1.1 does not report the generic global access
    checking table member entries as non-compliant.
    

Temporary fix

Comments

APAR Information

  • APAR number

    OA50640

  • Reported component name

    ZSEC BASE,ADMIN

  • Reported component ID

    5655T0100

  • Reported release

    211

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2016-06-03

  • Closed date

    2016-06-13

  • Last modified date

    2016-07-04

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

    UA81967 UA81968

Modules/Macros

  •    CKAPB711 CKAPC711
    

Fix information

  • Fixed component name

    ZSEC BASE,ADMIN

  • Fixed component ID

    5655T0100

Applicable component levels

  • R211 PSY UA81967

       UP16/06/14 P F606

  • R220 PSY UA81968

       UP16/06/14 P F606

Fix is available

  • Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.

[{"Business Unit":{"code":"BU048","label":"IBM Software"}, "Product":{"code":"SSCE68R","label":"zSecure Admin"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"211","Edition":""}]

Document Information

Modified date:
04 July 2016