STIGQter STIGQter: STIG Summary: IBM z/OS ACF2 Security Technical Implementation Guide Version: 9 Release: 9 Benchmark Date: 01 Jul 2026:

ICSF resource class(es) must be defined to the ACF2 GSO CLASMAP record in accordance with security requirements.

DISA Rule

SV-275965r1225884_rule

Vulnerability Number

V-275965

Group Title

SRG-OS-000080-GPOS-00048

Rule Version

ACF2-IC-000050

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Evaluate the impact associated with implementation of the control option. Develop a plan of action to implement the control option as specified in the example below.

Define the GSO CLASMAP records to include CRYPTOZ, CSFKEYS, CSFSERV, GCSFKEYS , GXCSFKEY, and XCSFKEY classes. Ensure resource classes are uniquely defined.

Example:
ACF
SET CONTROL (GSO)
INSERT CLASMAP.EJBROLE RESOURCE(EJBROLE) RSRCTYPE(EJB) ENTITYLN(nn)
F ACF2,REFRESH(ALL)

Check Contents

From the ISPF Command shell, enter:
SET CONTROL (GSO)
SHOW CLASMAP

If the CLASMAP records include CRYPTOZ, CSFKEYS, CSFSERV, GCSFKEYS , GXCSFKEY, and XCSFKEY resource classes, this is not a finding.

Vulnerability Number

V-275965

Documentable

False

Rule Version

ACF2-IC-000050

Severity Override Guidance

From the ISPF Command shell, enter:
SET CONTROL (GSO)
SHOW CLASMAP

If the CLASMAP records include CRYPTOZ, CSFKEYS, CSFSERV, GCSFKEYS , GXCSFKEY, and XCSFKEY resource classes, this is not a finding.

Check Content Reference

M

Target Key

4100