STIGQter STIGQter: STIG Summary: IBM zSecure Suite Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 02 Apr 2025:

XFACILIT class, or alternate class if specified in module CKRSITE, must be active.

DISA Rule

SV-259738r961863_rule

Vulnerability Number

V-259738

Group Title

SRG-APP-000516-MFP-000195

Rule Version

ZSEC-00-000260

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Ensure the resource class that is configured in CKRSITE for zSecure security checks is active in the RACF class descriptor table. The default class is XFACILIT. IBM Security zSecure recommends the generic be activated.

Following is a sample command:

SETROPTS CLASSACT(XFACILIT) or SETROPTS CLASSACT(<configured resource class for access checks>)

Check Contents

Run the CARLa command SHOW CKRSITE. The output of this command reveals which resource class is configured for handling the zSecure security checks. The default resource class is XFACILIT.

Verify in the class descriptor table that the configured zSecure resource class is active.

If the configured zSecure resource class is not active, this is a finding.

Vulnerability Number

V-259738

Documentable

False

Rule Version

ZSEC-00-000260

Severity Override Guidance

Run the CARLa command SHOW CKRSITE. The output of this command reveals which resource class is configured for handling the zSecure security checks. The default resource class is XFACILIT.

Verify in the class descriptor table that the configured zSecure resource class is active.

If the configured zSecure resource class is not active, this is a finding.

Check Content Reference

M

Target Key

5574