STIGQter STIGQter: STIG Summary: IBM z/OS RACF Security Technical Implementation Guide Version: 9 Release: 9 Benchmark Date: 01 Jul 2026:

The ICSF resource class(es) must be active in accordance with security requirements.

DISA Rule

SV-275953r1137691_rule

Vulnerability Number

V-275953

Group Title

SRG-OS-000080-GPOS-00048

Rule Version

RACF-IC-000060

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Evaluate the impact associated with implementation of the control option. Develop a plan of action to implement the control option as specified in the example below:

The RACF Command SETRopts LIST will show the status of RACF Controls including a list of ACTIVE classes.

The above Classes are activated with the command:
SETRopts CLASSACT(CRYPTOZ, CSFKEYS, CSFSERV, GCSFKEYS, GXCSFKEY, XCSFKEY

Check Contents

From the ISPF command shell, enter:
SETRopts list

If the ACTIVE CLASSES list the CRYPTOZ, CSFKEYS, CSFSERV, GCSFKEYS , GXCSFKEY, and XCSFKEY resource classes, this is not a finding.

Vulnerability Number

V-275953

Documentable

False

Rule Version

RACF-IC-000060

Severity Override Guidance

From the ISPF command shell, enter:
SETRopts list

If the ACTIVE CLASSES list the CRYPTOZ, CSFKEYS, CSFSERV, GCSFKEYS , GXCSFKEY, and XCSFKEY resource classes, this is not a finding.

Check Content Reference

M

Target Key

4101