STIGQter STIGQter: STIG Summary: z/OS CSSMTP for TSS Security Technical Implementation Guide Version: 7 Release: 1 Benchmark Date: 02 Jul 2025:

IBM Communications Server Simple Mail Transfer Protocol (CSSMTP) Started Task name is not properly identified and/or defined to the system Access Control Program (ACP).

DISA Rule

SV-224667r1116166_rule

Vulnerability Number

V-224667

Group Title

SRG-OS-000104

Rule Version

ZSMTT030

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

The IBM CSSMTP system programmer and the ISSO will ensure that a product's Started Task(s) is properly identified and/or defined to the System ACP.

If the product requires a Started Task, verify that it is properly defined to the System ACP with the proper attributes.

Most installation manuals will indicate how the Started Task is identified and any additional attributes that must be specified.

A sample is provided here:

TSS CREATE(CSSMTP) TYPE(USER) -
NAME('IBM CSSMTP') DEPT(xxxx) -
FAC(STC) -
PASS(xxxxxxxx,0) -
SOURCE(INTRDR) NOSUSPEND

Check Contents

Refer to the following report produced by the TSS Data Collection:

- TSSCMDS.RPT(@ACIDS)

Review each IBM CSSMTP STC/Batch ACID(s) for the following:

Defined with Facility of STC (the TSS FACILITY Matrix Table entry defined for this product), and/or BATCH for CSSMTP.

Is sourced to the INTRDR.

Vulnerability Number

V-224667

Documentable

False

Rule Version

ZSMTT030

Severity Override Guidance

Refer to the following report produced by the TSS Data Collection:

- TSSCMDS.RPT(@ACIDS)

Review each IBM CSSMTP STC/Batch ACID(s) for the following:

Defined with Facility of STC (the TSS FACILITY Matrix Table entry defined for this product), and/or BATCH for CSSMTP.

Is sourced to the INTRDR.

Check Content Reference

M

Target Key

4183