STIGQter STIGQter: STIG Summary: z/OS IBM CICS Transaction Server for TSS Security Technical Implementation Guide Version: 7 Release: 2 Benchmark Date: 01 Oct 2025:

CICS userids are not defined and/or controlled in accordance with proper security requirements.

DISA Rule

SV-224736r1145859_rule

Vulnerability Number

V-224736

Group Title

SRG-OS-000080

Rule Version

ZCICT041

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Ensure the CICS region is defined to the PROPCNTL resource class.

Example:

TSS ADDTO(owning acid) PROPCNTL(CICS region acid)

Check Contents

Refer to the following report produced by the TSS Data Collection:

- TSSCMDS.RPT(WHOOPROP).

Refer to the CICS Systems Programmer Worksheets filled out from previous vulnerability ZCIC0010.

If the CICS region is defined to the PROPCNTL resource class, this is not a finding.

Vulnerability Number

V-224736

Documentable

False

Rule Version

ZCICT041

Severity Override Guidance

Refer to the following report produced by the TSS Data Collection:

- TSSCMDS.RPT(WHOOPROP).

Refer to the CICS Systems Programmer Worksheets filled out from previous vulnerability ZCIC0010.

If the CICS region is defined to the PROPCNTL resource class, this is not a finding.

Check Content Reference

M

Target Key

4195