Auditors Checklist
Auditors Checklist
Note: In the Value column, the number of exclamation marks (!) indicates the value of the item to the audit, where !!! is critical and !! is important.
Data Set Security
Value Found setting or usage if
!!!=critical Audit Question Where to verify the setting or usage Recommended setting or usage different from
!!=important recommendation
!!! Is the Alternate ID enabled? C1DEFLTS table Type=MAIN section RACFUID= alternateID-name
ENABLE_ALTID_USS_SECURITY=(ON,nn)--
If used, is the Alternate ID enabled for USS Enables Alternate ID support for UNIX USS
!!! files and directories? ENCOPTBL, Options table files.
!!! How often is data validation performed? Ask the administrator Daily
Packages
Value Found setting or usage if
!!!=critical Audit Question Where to verify the setting or usage Recommended setting or usage different from
!!=important recommendation
Are security authorizations checked for Site Options report Package Processing
every action in a Package for the user ID Options section or C1DEFLTS Type=MAIN C1DEFLTS parameter, PKGISEC=Y or no value
requesting the Package inspect? section PKGISEC=
Which approver groups protect which
Environment and how are these approver
groups defined? CONRPT10
Which approver groups are used in which
inventory areas? CONRPT11
Do all generate processors include the Observe the administrator run the Search Each move processor should include
FOOTPRNT=CREATE statement? utility for FOOTPRINT=CREATE in processor FOOTPRNT=VERIFY
JCL. Review the JCL for each Processor.
Do all move processors include the Observe the administrator run the Search Each generate processor should include
FOOTPRNT=VERIFY statement? utility for FOOTPRINT=VERIFY in processor FOOTPRNT=CREATE
JCL. Review the JCL for each Processor.