STIGQter STIGQter: STIG Summary: zOS WebSphere MQ for ACF2 Security Technical Implementation Guide Version: 7 Release: 3 Benchmark Date: 01 Jul 2026:

WebSphere MQ RESLEVEL resources in the appropriate ADMIN resource class must be protected in accordance with security requirements.

DISA Rule

SV-224370r1144174_rule

Vulnerability Number

V-224370

Group Title

SRG-OS-000080

Rule Version

ZWMQ0060

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Ensure that a ssid.RESLEVEL profile is only defined for each queue manager.

Ensure the following items are in effect:

Note: ssid is the queue manager name (a.k.a., subsystem identifier).

A RESLEVEL resource (i.e., ssid.RESLEVEL) is defined for each queue manager to TYPE(MQA) (i.e., MQADMIN or MZADMIN resource class) with a default access of PREVENT.
Access authorization to these RESLEVEL resources restricts all access. No users are permitted access to ssid.RESLEVEL resources.

Example:

$KEY(ssid) TYPE(MQA)
RESLEVEL UID(*) PREVENT

Check Contents

Refer to the following report produced by the dataset and Resource Data Collection:

- SENSITVE.RPT(MQADMIN).
- SENSITVE.RPT(MXADMIN).
- ACF2CMDS.RPT(RESOURCE) - Alternate report.

Automated Analysis
Refer to the following report produced by the dataset and Resource Data Collection:

- PDI(ZWMQ0060).

If the following guidance is true, this is not a finding.

Note: ssid is the queue manager name (a.k.a., subsystem identifier).

A RESLEVEL resource (i.e., ssid.RESLEVEL) is defined for each queue manager to TYPE(MQA) or TYPE(MXA) (i.e., MQADMIN or MXADMIN resource class, if SCYCASE is set to MIXED) with a default access of PREVENT.

Access authorization to these RESLEVEL resources restricts all access. No users are permitted access to ssid.RESLEVEL resources.

Vulnerability Number

V-224370

Documentable

False

Rule Version

ZWMQ0060

Severity Override Guidance

Refer to the following report produced by the dataset and Resource Data Collection:

- SENSITVE.RPT(MQADMIN).
- SENSITVE.RPT(MXADMIN).
- ACF2CMDS.RPT(RESOURCE) - Alternate report.

Automated Analysis
Refer to the following report produced by the dataset and Resource Data Collection:

- PDI(ZWMQ0060).

If the following guidance is true, this is not a finding.

Note: ssid is the queue manager name (a.k.a., subsystem identifier).

A RESLEVEL resource (i.e., ssid.RESLEVEL) is defined for each queue manager to TYPE(MQA) or TYPE(MXA) (i.e., MQADMIN or MXADMIN resource class, if SCYCASE is set to MIXED) with a default access of PREVENT.

Access authorization to these RESLEVEL resources restricts all access. No users are permitted access to ssid.RESLEVEL resources.

Check Content Reference

M

Target Key

4133