STIGQter STIGQter: STIG Summary: IBM z/OS ACF2 Security Technical Implementation Guide Version: 9 Release: 9 Benchmark Date: 01 Jul 2026:

ICSF resources must be protected in accordance with security requirements.

DISA Rule

SV-275951r1225882_rule

Vulnerability Number

V-275951

Group Title

SRG-OS-000080-GPOS-00048

Rule Version

ACF2-IC-000060

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Evaluate the impact associated with implementation of the control option. Develop a plan of action to implement the control option as specified in the example below.

Define the GSO CLASMAP records to include the (CRYPTOZ, CSFKEYS, CSFSERV, GCSFKEYS , GXCSFKEY, and XCSFKEY) classes. Ensure resource classes are uniquely defined.

Example:
ACF
SET CONTROL (GSO)
INSERT CLASMAP.CSFKEYS RESOURCE(CSFKEYS) RSRCTYPE(CSK) ENTITYLN(nn)
F ACF2,REFRESH(ALL)

Check Contents

From the ISPF Command Shell, enter:

ACF
SET RESOURCE(<rsctype>)
List Like(-)

Consult the ICSF administrator, security administrator, and the site security plan for appropriate access.

If the ACF2 rules for each resource are restrictive to the appropriate users, this is not a finding.

Vulnerability Number

V-275951

Documentable

False

Rule Version

ACF2-IC-000060

Severity Override Guidance

From the ISPF Command Shell, enter:

ACF
SET RESOURCE(<rsctype>)
List Like(-)

Consult the ICSF administrator, security administrator, and the site security plan for appropriate access.

If the ACF2 rules for each resource are restrictive to the appropriate users, this is not a finding.

Check Content Reference

M

Target Key

4100