STIGQter STIGQter: STIG Summary: IBM z/OS ACF2 Security Technical Implementation Guide Version: 9 Release: 9 Benchmark Date: 01 Jul 2026:

IBM z/OS FTP.DATA configuration statements for the FTP Server must be specified in accordance with requirements.

DISA Rule

SV-255895r1225874_rule

Vulnerability Number

V-255895

Group Title

SRG-OS-000480-GPOS-00227

Rule Version

ACF2-FT-000120

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the FTP configuration to include the UMASK statement with a value of "077".

If the FTP Server requires a UMASK value less restrictive than "077", requirements should be justified and documented with the ISSO.

Check Contents

Refer to the Data configuration file specified on the SYSFTPD DD statement in the FTP started task JCL.

If the UMASK statement is coded with a value of "077", this is not a finding.

Vulnerability Number

V-255895

Documentable

False

Rule Version

ACF2-FT-000120

Severity Override Guidance

Refer to the Data configuration file specified on the SYSFTPD DD statement in the FTP started task JCL.

If the UMASK statement is coded with a value of "077", this is not a finding.

Check Content Reference

M

Target Key

4100