STIGQter STIGQter: STIG Summary: IBM z/OS TSS Security Technical Implementation Guide Version: 9 Release: 9 Benchmark Date: 01 Jul 2026:

zOSMF resource class(es) must be properly owned in accordance with security requirements.

DISA Rule

SV-275959r1137691_rule

Vulnerability Number

V-275959

Group Title

SRG-OS-000080-GPOS-00048

Rule Version

TSS0-ZO-000010

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Evaluate the impact associated with implementation of the control option. Develop a plan of action to implement the control option as specified in the example below:

The TSS Command WHOOWNS should identify any missing resource classes.
The ADDTO (RDT) can be used to define resources to the Resource Descriptor Table.
Ex. TSS ADDTO(RDT) RESCLAS(EJBROLE) ACLS6(READ)
Use the ADDTO command function to assign appropriate resource ownership.

Check Contents

OSMF resource class(es) must be properly owned in accordance with security requirements.

From the ISPF command shell, enter:

TSS WHOOWNS <CLASS>

If each of the following classes are properly owned, this is not a finding.
EJBROLE
LOGSTRM
SERVER
TSOPROC
ZMFAPLA
ZMFCLOUD

Vulnerability Number

V-275959

Documentable

False

Rule Version

TSS0-ZO-000010

Severity Override Guidance

OSMF resource class(es) must be properly owned in accordance with security requirements.

From the ISPF command shell, enter:

TSS WHOOWNS <CLASS>

If each of the following classes are properly owned, this is not a finding.
EJBROLE
LOGSTRM
SERVER
TSOPROC
ZMFAPLA
ZMFCLOUD

Check Content Reference

M

Target Key

4102