STIGQter STIGQter: STIG Summary: IBM z/OS TSS Security Technical Implementation Guide Version: 9 Release: 9 Benchmark Date: 01 Jul 2026:

zOSMF resources must be protected in accordance with security requirements.

DISA Rule

SV-275960r1169908_rule

Vulnerability Number

V-275960

Group Title

SRG-OS-000080-GPOS-00048

Rule Version

TSS0-ZO-000020

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure ICSF access for resources in accordance with site security plan.

Check Contents

From the ISPF command shell, enter WHOOWNS as follows:
EJBROLE *
LOGSTRM *
SERVER *
TSOPROC *
ZMFAPLA *
ZMFCLOUD *

For each resource defined, enter:
TSS WHOHAS <resource>(resource item>

If TSS access rules for each resource are restricted to appropriate users as found in Appendix A in the zOSMF Configuration Guide: Security Structures for z/OSMF Requirements for the Security Configuration tables, this is not a finding.

Vulnerability Number

V-275960

Documentable

False

Rule Version

TSS0-ZO-000020

Severity Override Guidance

From the ISPF command shell, enter WHOOWNS as follows:
EJBROLE *
LOGSTRM *
SERVER *
TSOPROC *
ZMFAPLA *
ZMFCLOUD *

For each resource defined, enter:
TSS WHOHAS <resource>(resource item>

If TSS access rules for each resource are restricted to appropriate users as found in Appendix A in the zOSMF Configuration Guide: Security Structures for z/OSMF Requirements for the Security Configuration tables, this is not a finding.

Check Content Reference

M

Target Key

4102