STIGQter STIGQter: STIG Summary: IBM z/OS ACF2 Security Technical Implementation Guide Version: 9 Release: 9 Benchmark Date: 01 Jul 2026:

ACF2 Classes required to properly security the z/OS UNIX environment must be ACTIVE.

DISA Rule

SV-223436r1225668_rule

Vulnerability Number

V-223436

Group Title

SRG-OS-000080-GPOS-00048

Rule Version

ACF2-ES-000150

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Define the CLASMAP DEFINITIONS to include entries for the FACILITY, SURROGAT, and UNIXPRIV resource classes.

NOTE: TYPE CODES values should be unique for each resource. The default TYPE CODE values should be FAC, SUR, and UNI.

Example:
TSO ACF
SHOW CLASMAP

ACF
SET CONTROL(GSO)
INSERT CLASMAP.FACILITY RESOURCE(FACILITY) RSRCTYPE(FAC) ENTITYTLN (39)

Check Contents

From the ISPF Command Shell enter:
ACF
SET CONTROL(GSO)
SHOW CLASMAP

If the CLASMAP DEFINITIONS list does not include entries for the FACILITY, SURROGAT, and UNIXPRIV resource classes, this is a finding.

NOTE: TYPE CODES values should be unique for each resource. The default TYPE CODE values should be FAC, SUR, and UNI.

Vulnerability Number

V-223436

Documentable

False

Rule Version

ACF2-ES-000150

Severity Override Guidance

From the ISPF Command Shell enter:
ACF
SET CONTROL(GSO)
SHOW CLASMAP

If the CLASMAP DEFINITIONS list does not include entries for the FACILITY, SURROGAT, and UNIXPRIV resource classes, this is a finding.

NOTE: TYPE CODES values should be unique for each resource. The default TYPE CODE values should be FAC, SUR, and UNI.

Check Content Reference

M

Target Key

4100