9.1 Ensure 'zosSecurity-1.0' feature is 'enabled' for SAF authorization

Information

The SAF role mapper should be used to perform SAF authorization checks when accessing applications.

On the z/OS platform using the native z/OS facilities like the SAF authorization is recommended for application access checks.

Solution

Configure the zosSecurity-1.0 feature and set the safAuthorization element in ${server.config.dir}/configDropins/overrides/<any file name>.xml

<feature>zosSecurity-1.0</feature>
<safAuthorization id="saf" />

See Also

https://workbench.cisecurity.org/benchmarks/7724

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2(1), CSCv7|16.2

Plugin: Unix

Control ID: 6f2558618a211b31d0ee7106439965e32218b36d8242383a6cd2a7ec87af92c3