STIGQter STIGQter: STIG Summary: z/OS CL/SuperSession for ACF2 Security Technical Implementation Guide Version: 7 Release: 2 Benchmark Date: 01 Oct 2025:

CL/SuperSession Started Task name is not properly identified / defined to the system ACP.

DISA Rule

SV-224286r1144190_rule

Vulnerability Number

V-224286

Group Title

SRG-OS-000104

Rule Version

ZCLSA030

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

The systems programmer and ISSO will ensure that the started task for CL/SuperSession is properly defined.

Review all session manager security parameters and control options for compliance. Develop a plan of action and implement the changes as specified.

Define the started task userid KLS for CL/SuperSession.

Example:

INSERT KLS NAME(STC, CL/SuperSession) MUSASS NO-SMC STC

Check Contents

Refer to the following report produced by the ACF2 Data Collection:

- ACF2CMDS.RPT(ATTSTC).

Verify that the logonid(s) for the CL/SUPERSESSION started task(s) is (are) properly defined. If the following attributes are defined, this is not a finding.

STC
MUSASS
NO-SMC

Vulnerability Number

V-224286

Documentable

False

Rule Version

ZCLSA030

Severity Override Guidance

Refer to the following report produced by the ACF2 Data Collection:

- ACF2CMDS.RPT(ATTSTC).

Verify that the logonid(s) for the CL/SUPERSESSION started task(s) is (are) properly defined. If the following attributes are defined, this is not a finding.

STC
MUSASS
NO-SMC

Check Content Reference

M

Target Key

4117