STIGQter STIGQter: STIG Summary: IBM z/OS TSS Security Technical Implementation Guide Version: 9 Release: 9 Benchmark Date: 01 Jul 2026:

ICSF resource class(es) must be properly owned in accordance with security requirements.

DISA Rule

SV-275961r1169902_rule

Vulnerability Number

V-275961

Group Title

SRG-OS-000080-GPOS-00048

Rule Version

TSS0-IC-000060

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Evaluate the impact associated with implementation of the control option. Develop a plan of action to implement the control option as specified in the example below:

The TSS Command WHOOWNS should identify any missing resource classes.
The ADDTO (RDT) can be used to define resources to the Resource Descriptor Table.

Ex. TSS ADDTO(RDT) RESCLAS(CRYPTOZ) ACLS6(READ)
Use the ADDTO command function to assign CRYPTOZ appropriate resource ownership.

Check Contents

From the ISPF command shell, enter:

TSS WHOOWNS <CLASS>

If each of the following classes are properly owned, this is not a finding:
CRYPTOZ
CSFKEYS
CSFSERV
GCSFKEYS
XCSFKEY

Vulnerability Number

V-275961

Documentable

False

Rule Version

TSS0-IC-000060

Severity Override Guidance

From the ISPF command shell, enter:

TSS WHOOWNS <CLASS>

If each of the following classes are properly owned, this is not a finding:
CRYPTOZ
CSFKEYS
CSFSERV
GCSFKEYS
XCSFKEY

Check Content Reference

M

Target Key

4102