IBM Support

OA52086: PCI-DSS RULE 7.1.1 DOES NOT EXCLUDE CHECKS FOR GENERIC GLOBAL MEMBERS

A fix is available

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • PCI-DSS rule 7.1.1 does not exclude checks for generic global
    members
    

Local fix

  • n/a
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED: Users of zSecure Audit exploiting the        *
    *                 PCI-DSS compliance rule set 7.1.1.           *
    ****************************************************************
    * PROBLEM DESCRIPTION: The zSecure Audit PCI-DSS compliance    *
    *                      rule set 7.1.1 still reports the        *
    *                      generic access checking table members   *
    *                      as non-compliant.                       *
    ****************************************************************
    * RECOMMENDATION: Apply the PTF propvided.                     *
    ****************************************************************
    The PCI-DSS compliance rule set 7.1.1 (Access rights for
    for privileged user IDs must be restricted to least privileges
    to perform job responsibilities) reports generic global access
    checking table members as non-compliant.
    

Problem conclusion

  • zSecure Audit has been modified so that the PCI-DSS compliance
    rule set 7.1.1 does not report the generic global access
    checking table member entries as non-compliant.
    

Temporary fix

Comments

APAR Information

  • APAR number

    OA52086

  • Reported component name

    ZSEC BASE,ADMIN

  • Reported component ID

    5655T0100

  • Reported release

    220

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2017-02-08

  • Closed date

    2017-03-08

  • Last modified date

    2017-04-03

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

    UA91290 UA91291

Modules/Macros

  •    CKAPC711
    

Fix information

  • Fixed component name

    ZSEC BASE,ADMIN

  • Fixed component ID

    5655T0100

Applicable component levels

  • R220 PSY UA91290

       UP17/03/09 P F703

  • R221 PSY UA91291

       UP17/03/09 P F703

Fix is available

  • Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.

[{"Business Unit":{"code":"BU048","label":"IBM Software"}, "Product":{"code":"SSCE68R","label":"zSecure Admin"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"220","Edition":""}]

Document Information

Modified date:
03 April 2017