STIGQter STIGQter: STIG Summary: z/OS CL/SuperSession for TSS Security Technical Implementation Guide Version: 7 Release: 2 Benchmark Date: 01 Oct 2025:

CL/SuperSession Started Task name is not properly identified/defined to the system ACP.

DISA Rule

SV-224653r1145875_rule

Vulnerability Number

V-224653

Group Title

SRG-OS-000104

Rule Version

ZCLST030

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

The Systems Programmer and ISSO will ensure that the started task for CL/SuperSession is properly defined.

Review all session manager security parameters and control options for compliance. Develop a plan of action and implement the changes as specified.

Define the started task userid KLS for CL/SuperSession.

Example:

TSS CRE(KLS) DEPT(Dept) NAME('CL/SuperSession STC') -
FAC(STC) MASTFAC(KLS) PASSWORD(password,0) -
SOURCE(INTRDR) NOSUSPEND

Check Contents

Refer to the following report produced by the TSS Data Collection:

- TSSCMDS.RPT(@ACIDS).

Review the CL/SuperSession STC/Batch ACID(s). If the following attributes are defined, this is not a finding.

FACILITY(STC, BATCH)
PASSWORD(xxxxxxxx,0)
SOURCE(INTRDR)
NOSUSPEND
MASTFAC(KLS)

Vulnerability Number

V-224653

Documentable

False

Rule Version

ZCLST030

Severity Override Guidance

Refer to the following report produced by the TSS Data Collection:

- TSSCMDS.RPT(@ACIDS).

Review the CL/SuperSession STC/Batch ACID(s). If the following attributes are defined, this is not a finding.

FACILITY(STC, BATCH)
PASSWORD(xxxxxxxx,0)
SOURCE(INTRDR)
NOSUSPEND
MASTFAC(KLS)

Check Content Reference

M

Target Key

4181