STIGQter STIGQter: STIG Summary: z/OS CL/SuperSession for TSS Security Technical Implementation Guide Version: 7 Release: 2 Benchmark Date: 01 Oct 2025:

CL/SuperSession must be properly configured to generate SMF records for audit trail and accounting reports.

DISA Rule

SV-224650r1145866_rule

Vulnerability Number

V-224650

Group Title

SRG-OS-000018

Rule Version

ZCLS0041

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Ensure that the Session Manager generates SMF records for audit trail and accounting reports.

To provide an audit trail of user activity in CL/SuperSession, configure the Network Accounting Facility (NAF) to require SMF recording of accounting and audit data. Accounting to the journal data set is optional at the discretion of the site. To accomplish this for version 3 of CL/SuperSession, configure the following NAF startup parameters in the KLKINNAF member of the RLSPARM initialization parameter library as follows:

DSNAME= dsname - Name of the NAF journal data set. Required only if the site is collecting accounting and audit data in the journal data set in addition to the SMF data.

MOD - If the journal data set is used, this parameter should be set to ensure that logging data in the data set is not overwritten.

SMF=nnn - SMF record number. This field is mandatory to ensure that CL/SuperSession data is always written to the SMF files.

Check Contents

Version 3 of CL/SuperSession
Review the member KLKINNAF in the TLVPARM DD statement concatenation of the CL/SuperSession STC procedure to determine SMF number. (This member is located in SYS3.OMEGAMON.qualifier.RLSPARM.)

Version 2 of CL/SuperSession
Review the member KLVINNAF in the TLVPARM DD statement concatenation of the CL/SuperSession STC procedure to determine SMF number. (This member is located in SYS3.OMEGAMON.qualifier.RLSPARM.)

Refer to the following report produced by the z/OS Data Collection:

- EXAM.RPT(SMFOPTS).

Automated Analysis
Refer to the following report produced by the z/OS Data Collection:

- PDI(ZCLS0041).

If the SMF= field specifies an SMF record number and the SMFOPTS report specifies that SMF is writing the record number specified by SMF=, this is not a finding.

Vulnerability Number

V-224650

Documentable

False

Rule Version

ZCLS0041

Severity Override Guidance

Version 3 of CL/SuperSession
Review the member KLKINNAF in the TLVPARM DD statement concatenation of the CL/SuperSession STC procedure to determine SMF number. (This member is located in SYS3.OMEGAMON.qualifier.RLSPARM.)

Version 2 of CL/SuperSession
Review the member KLVINNAF in the TLVPARM DD statement concatenation of the CL/SuperSession STC procedure to determine SMF number. (This member is located in SYS3.OMEGAMON.qualifier.RLSPARM.)

Refer to the following report produced by the z/OS Data Collection:

- EXAM.RPT(SMFOPTS).

Automated Analysis
Refer to the following report produced by the z/OS Data Collection:

- PDI(ZCLS0041).

If the SMF= field specifies an SMF record number and the SMFOPTS report specifies that SMF is writing the record number specified by SMF=, this is not a finding.

Check Content Reference

M

Target Key

4181