IBM i : Limit Security Officer (QLMTSECOFR) - '1'

Information

The Limit Security Officer (QLMTSECOFR) system value controls whether a user with all-object (*ALLOBJ) or service (*SERVICE) special authority can sign on to any workstation. Limiting powerful user profiles to certain well-controlled workstations provides security protection.

Solution

Set QLMTSECOFR to 1, so that a user with *ALLOBJ or *SERVICE special authority can sign on at a workstation only if that user is specifically authorized (that is, given *CHANGE authority) to the workstation or if user profile QSECOFR is authorized (given *CHANGE authority) to the workstation. This authority cannot come from public authority.

See Also

https://www.ibm.com/support/knowledgecenter/ssw_ibm_i_72/rzarl/sc415302.pdf

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(1)

Plugin: AS/400

Control ID: c36996e758af210650be8835c40728677a7c995e24787c2da28ff5033533d6d3