STIGQter STIGQter: STIG Summary: IBM z/OS RACF Security Technical Implementation Guide Version: 9 Release: 9 Benchmark Date: 01 Jul 2026:

IBM Integrated Crypto Service Facility (ICSF) Started task(s) must be properly defined to the STARTED resource class for RACF.

DISA Rule

SV-255938r958482_rule

Vulnerability Number

V-255938

Group Title

SRG-OS-000104-GPOS-00051

Rule Version

RACF-IC-000050

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Ensure that a product's started task(s) is (are) properly identified and/or defined to the System ACP.

A unique userid must be assigned for the IBM Integrated Crypto Service Facility (ICSF) started task(s) thru a corresponding STARTED class entry.

The following sample set of commands is shown here as a guideline:

rdef started CSFSTART.** uacc(none) owner(admin) audit(all(read)) stdata(user(CSFSTART) group(stc))

setr racl(started) ref

Check Contents

Execute the RACF DSMON report for RACSPT

if the IBM Integrated Crypto Service Facility (ICSF) started task(s) is (are) not defined to the STARTED resource class profile and/or ICHRIN03 table entry this is a finding

Vulnerability Number

V-255938

Documentable

False

Rule Version

RACF-IC-000050

Severity Override Guidance

Execute the RACF DSMON report for RACSPT

if the IBM Integrated Crypto Service Facility (ICSF) started task(s) is (are) not defined to the STARTED resource class profile and/or ICHRIN03 table entry this is a finding

Check Content Reference

M

Target Key

4101