Comprehensive report listing in SPM with ESM compatibility


This topic serves as a centralized reference for all reports available in BMC AMI Security Policy Manager (SPM), organized by the enterprise security manager (ESM) platforms—RACF, CA Top Secret (TSS), and CA ACF2. It is designed to help you determine report availability and platform compatibility. Use this reference to quickly identify whether a specific report is supported and which ESM integration it applies to.

The following table lists the 655 reports in SPM. The columns from left to right indicate the UI navigation path to access a report.

MenuMenu groupMenu group itemReport titleRACFTSSACF2Number of reports per menu
Data SetsNon-Fully Qualified GenericAPF APF Data Sets without Fully Qualified Generic ProfileY



APF Data Sets without Fully Qualified Permit
Y


APF Data Sets without Fully Qualified Rule

Y


Other Other Data Sets with Non-Fully Qualified Generic profilesY

Other Data Sets without Fully Qualified Permit
Y
Other Data Sets without Fully Qualified Rule

Y

Sensitive Data SetsUACC > None Sensitive Data Sets with UACC > NoneY



ID(*) > None Sensitive Data Sets with ID(*) > NoneY



WARN Sensitive Data Sets with WARNY



Uncatalogued Uncatalogued Sensitive Data SetsYYY


Inappropriate Audit Sensitive Data Sets with Inappropriate AuditY



Level = 99 Sensitive Data Sets with Level = 99Y



All All Sensitive Data SetsYY


With *ALL* Access > None All sensitive resources with *ALL* ACCESS > None
Y


Other datasets With UID(*) Access > None All sensitive datasets with UID(*) ACCESS > None

Y

APF Data SetsAPF datasets With UID(*) Access > None APF libraries with UID(*) access > None

Y


APF libraries with inappropriate logging APF libraries with Inappropriate Logging - should be WRITE(L) and ALLOC(L)

Y


APF libraries with no Rule with UID(*) preventing accessAPF libraries with no Rule with UID(*) preventing access

Y21
Sensitive Commands(No title)z/OS.SETPROGz/OS.SETPROG CommandsYYY


SETROPTS SETROPTS CommandsY



All z/OS Commands All z/OS CommandsYYY7
ResourcesMissing PermissionsOPERCMD Missing OPERCMD PermissionsYYY


STGADMIN Missing STGADMIN PermissionsYYY


UNIXPRIV Missing UNIXPRIV PermissionsYYY


Command Verifier Missing Command Verifier ProfilesYY


Certificate Missing Certificate PermissionsYYY

CertificatesAll PermissionsAll Certificate PermissionsYY


Expiring Expiring CertificatesYYY


Expired Expired CertificatesYYY


All All CertificatesYYY

Misconfigured SettingsCICS SIT Misconfigured CICS SIT SettingsYYY


IMS Misconfigured IMS SettingsYYY


DB2 Misconfigured DB2 SettingsYYY


MQ Misconfigured MQ SettingsYYY

Software Security SettingsCICS SIT CICS SIT SettingsYYY


IMS IMS Security SettingsYYY


DB2 DB2 Security SettingsYYY


MQ MQ Security SettingsYYY

(No title)Recommended Security SettingsRecommended Profile and Security SettingsY



Permissions with Inappropriate Audit Resource Permissions with Inappropriate AuditYY


All PermissionsAll Resource PermissionsYY


Global Access Table Global Access TableY

55
System SettingsPPTEntries Specifying NOPASS PPT Entries Specifying NOPASS in ParmlibYYY


Entries Defined as NOSWAP PPT Entries Defined as NOSWAP in ParmlibYYY

(No title)Misconfigured Settings Misconfigured SettingsY



All Settings All SettingsYY


STC Entries with Unprotected User ID  Started Task Entries with Unprotected User IDYY


Inactive Monitored Jobs Inactive Monitored JobsYYY


Misconfigured Settings Misconfigured Settings
Y


TSSPARM SettingsTSSPARM Settings
Y
17
Users(No title)Specific User Activity  Detailed User ActivityYY


Weak Passwords  Users with Weak PasswordY



Special and Audit  Users with Special and AuditY



Operations Users with OperationsY



No Password Interval  Users with No Password IntervalY



UID(0) Users with UID(0)Y



Not used for 90 days  Users not used for 90 daysY



IBMUSER Not Revoked  IBMUSER Not RevokedY



Revoked Special Users  Revoked Special UsersY



Duplicate Names Users with Duplicate NamesY



File Transfers User File TransfersYYY


Inactive (Non-STC)All Inactive Non-STC Users
Y


ACF2 Privileges Users with ACF2 Privileges

Y


UID(0) Users with UID(0)

Y


Password interval<30  Users with password interval<30

Y


Sharing non-zero uid  Users sharing non-zero uid

Y


Users with Special, Operations, Auditor or ROAudit PrivilegeUsers with Special, Operations, Auditor or ROAudit PrivilegeY


ACIDsNo 'Last Used' DateACIDs with no 'Last Used' Date
Y


With NOxxxCHKACIDs with NOxxxCHK
Y


With Non-Expiring PasswordsACIDs with Non-Expiring Passwords
Y


With UID(0)ACIDs with UID(0)
Y
25
Compliance(No title)Access Violations Access ViolationsYY


Allowlist AllowlistsYYY6

Compliance ReportsOverview Compliance OverviewYYY1


All All Compliance ReportsYYY508


DISA STIG DISA STIG Compliance ReportsYYY319


z/OSz/OS Compliance ReportsYYY11


Db2 DB2 Compliance ReportsYYY15


RACF RACF Compliance ReportsY

31


USS USS Compliance ReportsYYY8


TCP/IP TCP/IP Compliance ReportsYYY12


CICS CICS Compliance ReportsYYY21


REXX REXX Compliance ReportsYYY21


CIS RACFCIS RACF Compliance ReportsY

41


PCI DSSPCI DSS RACF Compliance ReportsY

8


TSSTSS Compliance Reports
Y
21
RACFProfiles with…UACC > None Profiles with UACC > NoneY



ID(*) > None Profiles with ID(*) > NoneY



Warning Profiles with WarningY



Empty ACL Profiles with an Empty ACLY


GroupsOwner is not Supgroup Groups where the Owner is not the SupgroupY



Universal Settings Universal Group SettingsY

6
z/VM(No title)Allz/VM Rules SummaryY



Surrogate usersProtecting z/VM surrogate usersY



Logonby resourcesProtecting z/VM logonby resourcesY



AllowlistsProtecting z/VM allowlistsY

4
TSS(No title)Resources with *ALL* Access > NoneResources with *ALL* Access > None
Y
1
ACF2(No title)Access Rules Access Rules

Y


Resource Rules Resource Rules

Y


GSO/Password/Phrase Settings GSO/Password/Phrase Settings

Y

Rules with…UID(*) access > None Rules with UID(*) access > None

Y4

For more information about compliance reports supported in SPM, see:

 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*

BMC AMI Security Policy Manager 2.3