STIGQter STIGQter: STIG Summary: IBM z/OS ACF2 Security Technical Implementation Guide Version: 9 Release: 9 Benchmark Date: 01 Jul 2026:

zOSMF resources must be protected in accordance with security requirements.

DISA Rule

SV-275964r1225883_rule

Vulnerability Number

V-275964

Group Title

SRG-OS-000080-GPOS-00048

Rule Version

ACF2-ZO-000020

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Review the requirements for security setup requirements for the Security Configuration Assistant service in the zOSMF Configuration Guide.

Configure access for resources accordingly.

Check Contents

From ISPF command shell enter "acf".
For EJBROLE, LOGSTRM, SERVER, TSOPROC, ZMFAPLA AND ZMFCLOUD resources class, enter

SET RESOURCE (,rsrctype>)
List like(-)

If ACF2 access rules for each resource as defined in the Appendix A in the zOSMF Configuration Guide: Security Structures for z/OSMF Requirements for the Security Configuration tables, are restricted to appropriate users, this is not a finding.

Vulnerability Number

V-275964

Documentable

False

Rule Version

ACF2-ZO-000020

Severity Override Guidance

From ISPF command shell enter "acf".
For EJBROLE, LOGSTRM, SERVER, TSOPROC, ZMFAPLA AND ZMFCLOUD resources class, enter

SET RESOURCE (,rsrctype>)
List like(-)

If ACF2 access rules for each resource as defined in the Appendix A in the zOSMF Configuration Guide: Security Structures for z/OSMF Requirements for the Security Configuration tables, are restricted to appropriate users, this is not a finding.

Check Content Reference

M

Target Key

4100