STIGQter STIGQter: STIG Summary: IBM z/OS RACF Security Technical Implementation Guide Version: 9 Release: 9 Benchmark Date: 01 Jul 2026:

zOSMF resource class(es) must be active in accordance with security requirements.

DISA Rule

SV-275952r1137691_rule

Vulnerability Number

V-275952

Group Title

SRG-OS-000080-GPOS-00048

Rule Version

RACF-ZO-000010

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Evaluate the impact associated with implementation of the control option. Develop a plan of action to implement the control option as specified in the example below:

The RACF Command SETRopts LIST will show the status of RACF Controls including a list of ACTIVE classes.

The above Classes are activated with the command:
SETRopts CLASSACT(EJBROLE, LOGSTRM, SERVER, TSOPROC, ZMFAPLA, and ZMFCLOUD).

Check Contents

From the ISPF command shell enter:
SETRopts list

If the ACTIVE CLASSES list the EJBROLE, LOGSTRM, SERVER, TSOPROC, ZMFAPLA, and ZMFCLOUD, this is not a finding.

Vulnerability Number

V-275952

Documentable

False

Rule Version

RACF-ZO-000010

Severity Override Guidance

From the ISPF command shell enter:
SETRopts list

If the ACTIVE CLASSES list the EJBROLE, LOGSTRM, SERVER, TSOPROC, ZMFAPLA, and ZMFCLOUD, this is not a finding.

Check Content Reference

M

Target Key

4101