STIGQter STIGQter: STIG Summary: zOS WebSphere MQ for TSS Security Technical Implementation Guide Version: 7 Release: 3 Benchmark Date: 01 Jul 2026:

WebSphere MQ connection class resources must be protected properly.

DISA Rule

SV-225631r1146221_rule

Vulnerability Number

V-225631

Group Title

SRG-OS-000080

Rule Version

ZWMQ0052

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Review the following connection resources defined to the MQCONN or MXCONN resource class:

Resource Authorized Users
ssid.BATCH TSO and batch job ACIDs
ssid.CICS CICS region ACIDs
ssid.IMS IMS region ACIDs
ssid.CHIN Channel initiator ACIDs

Note: ssid is the queue manager name (a.k.a., subsystem identifier).

For all connection resources defined to the MQCONN or MXCONN resource class, ensure the following items are in effect:

Access authorization restricts access to the appropriate users as indicated above.
All access FAILUREs are logged.

The following is a sample of the commands required to allow a batch user (USER1) to connect to a queue manager (QM1):

TSS ADD(USER1) FAC(QM1MSTR)
TSS PER(USER1) MQCONN(QM1.BATCH) ACC(READ)

Check Contents

Refer to the following report produced by the TSS Data Collection:

- SENSITVE.RPT(WHOHMCON).

Review the following connection resources for each queue manager defined to the connection resource class:

Resource Authorized Users
ssid.BATCH TSO and batch job ACIDs
ssid.CICS CICS region ACIDs
ssid.IMS IMS region ACIDs
ssid.CHIN Channel initiator ACIDs

Note: ssid is the queue manager name (a.k.a., subsystem identifier).

For all connection resources defined to the MQCONN, if the following guidance is true, this is not a finding.

Access authorization restricts access to the appropriate users as indicated above.
All access FAILUREs are logged.

Vulnerability Number

V-225631

Documentable

False

Rule Version

ZWMQ0052

Severity Override Guidance

Refer to the following report produced by the TSS Data Collection:

- SENSITVE.RPT(WHOHMCON).

Review the following connection resources for each queue manager defined to the connection resource class:

Resource Authorized Users
ssid.BATCH TSO and batch job ACIDs
ssid.CICS CICS region ACIDs
ssid.IMS IMS region ACIDs
ssid.CHIN Channel initiator ACIDs

Note: ssid is the queue manager name (a.k.a., subsystem identifier).

For all connection resources defined to the MQCONN, if the following guidance is true, this is not a finding.

Access authorization restricts access to the appropriate users as indicated above.
All access FAILUREs are logged.

Check Content Reference

M

Target Key

4211