STIGQter STIGQter: STIG Summary: zOS WebSphere MQ for ACF2 Security Technical Implementation Guide Version: 7 Release: 3 Benchmark Date: 01 Jul 2026:

WebSphere MQ started tasks are not defined in accordance with the proper security requirements.

DISA Rule

SV-224358r1144160_rule

Vulnerability Number

V-224358

Group Title

SRG-OS-000104

Rule Version

ZWMQ0030

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

The ISSO will ensure that all WebSphere MQ started tasks are properly defined.

Review WebSphere MQ started tasks and ensure the following items are in effect:

Note: ssid is the queue manager name (a.k.a., subsystem identifier).
ssidMSTR is the name of a queue manager STC.
ssidCHIN is the name of a distributed queuing (a.k.a., channel initiator) STC.

Each WebSphere MQ started task is associated with a unique logonid.

Each WebSphere MQ STC logonid has the attributes of STC, MUSASS, and NOSMC.

Example:

SET LID
INSERT ssid.MSTR NAME(MQseries, STC) STC MUSASS NO-SMC

INSERT ssid.CHIN NAME(MQseries, STC) STC MUSASS NO-SMC

Check Contents

Refer to the following reports produced by the ACF2 Data Collection:

- ACF2CMDS.RPT(LOGONIDS).
- ACF2CMDS.RPT(ATTSTC).

Note: ssid is the queue manager name (a.k.a., subsystem identifier).

Provide a list of all WebSphere MQ Subsystem IDs (Queue managers) and Release levels.

ssidMSTR is the name of a queue manager STC.
ssidCHIN is the name of a distributed queuing (a.k.a., channel initiator) STC.

Review WebSphere MQ started tasks and verify the following items are in effect. If they are, this is not a finding.

Each ssidMSTR and ssidCHIN started task is associated with a unique logonid.
Each ssidMSTR and ssidCHIN STC logonid has the following attributes defined.

STC
MUSASS
NOSMC

Repeat these steps for each queue manager ssid.

Vulnerability Number

V-224358

Documentable

False

Rule Version

ZWMQ0030

Severity Override Guidance

Refer to the following reports produced by the ACF2 Data Collection:

- ACF2CMDS.RPT(LOGONIDS).
- ACF2CMDS.RPT(ATTSTC).

Note: ssid is the queue manager name (a.k.a., subsystem identifier).

Provide a list of all WebSphere MQ Subsystem IDs (Queue managers) and Release levels.

ssidMSTR is the name of a queue manager STC.
ssidCHIN is the name of a distributed queuing (a.k.a., channel initiator) STC.

Review WebSphere MQ started tasks and verify the following items are in effect. If they are, this is not a finding.

Each ssidMSTR and ssidCHIN started task is associated with a unique logonid.
Each ssidMSTR and ssidCHIN STC logonid has the following attributes defined.

STC
MUSASS
NOSMC

Repeat these steps for each queue manager ssid.

Check Content Reference

M

Target Key

4133