NCP (Net Work Control Program) Data set access authorization does not restricts UPDATE and/or ALLOCATE access to appropriate personnel.

Severity
Group ID
Group Title
Version
Rule ID
Date
STIG Version
mediumV-224487SRG-OS-000259ZFEP0015SV-224487r1144839_rule2025-09-277
Description
If components of the FEPs are not properly protected, they can be stolen, damaged, or disturbed. Without adequate physical security, unauthorized users can access the control panel, the operator console, and the diskette drive of the service subsystem. Therefore, they can interfere with the normal operations of the FEPs. Improper control of FEP components could compromise network operations.
ℹ️ Check
Refer to the following report produced by the Data Set and Resource Data Collection: - SENSITVE.RPT(NCPRPT). The ACP data set rules for NCP data sets restrict WRITE and/or greater access to authorized personnel (e.g., systems programming personnel), this is not a finding.
✔️ Fix
Identify Names of the following data sets used for installation and in development/production environments: - NCP system data sets - NCP source definition data sets - NCP load modules - NCP host dump data sets - NCP utility programs Have the ISSO validate that they are properly protected by the ACP. And that only authorized personnel are permitted UPDATE and/or ALLOCATE access (e.g., z/OS systems programming personnel).