STIGQter STIGQter: STIG Summary: IBM z/OS ACF2 Security Technical Implementation Guide Version: 9 Release: 9 Benchmark Date: 01 Jul 2026:

ACF2 security data sets and/or databases must be properly protected.

DISA Rule

SV-223514r1225744_rule

Vulnerability Number

V-223514

Group Title

SRG-OS-000134-GPOS-00068

Rule Version

ACF2-ES-000970

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure ACF2 READ and/or greater access rules for ACF2 files and/or databases as limited to system programmers and/or security personnel, and/or batch jobs that perform ACP maintenance.

READ access can be given to auditors and DASD batch. All accesses to ACP files and/or databases are logged.

Check Contents

Determine all associated ACF2 security data sets and/or databases.

If the ACF2 data set rules for ACF2 security data sets and/or databases restrict READ access to auditors and DASD batch, this is not a finding.

If the ACF2 data set rules for ACF2 security data sets and/or databases restrict READ and/or greater access to z/OS systems programming personnel, security personnel, and/or batch jobs that perform ACP maintenance, this is not a finding.

If all (i.e., failures and successes) data set access authorities (i.e., READ, WRITE, ALLOCATE, and CONTROL) for ACP security data sets and/or databases are logged, this is not a finding.

Vulnerability Number

V-223514

Documentable

False

Rule Version

ACF2-ES-000970

Severity Override Guidance

Determine all associated ACF2 security data sets and/or databases.

If the ACF2 data set rules for ACF2 security data sets and/or databases restrict READ access to auditors and DASD batch, this is not a finding.

If the ACF2 data set rules for ACF2 security data sets and/or databases restrict READ and/or greater access to z/OS systems programming personnel, security personnel, and/or batch jobs that perform ACP maintenance, this is not a finding.

If all (i.e., failures and successes) data set access authorities (i.e., READ, WRITE, ALLOCATE, and CONTROL) for ACP security data sets and/or databases are logged, this is not a finding.

Check Content Reference

M

Target Key

4100