STIGQter STIGQter: STIG Summary: IBM z/OS ACF2 Security Technical Implementation Guide Version: 8 Release: 2 Benchmark Date: 23 Apr 2021:

ACF2 Classes required to properly security the z/OS UNIX environment must be ACTIVE.

DISA Rule

SV-223436r533198_rule

Vulnerability Number

V-223436

Group Title

SRG-OS-000080-GPOS-00048

Rule Version

ACF2-ES-000150

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Define the CLASMAP DEFINITIONS to include entries for the FACILITY, SURROGAT, and UNIXPRIV resource classes.

NOTE: The default TYPE CODE values should be FAC, SUR, and UNI.

Example:
TSO ACF
SHOW CLASMAP

ACF
set control(go)
GSO
insert clasmap.fac resource(facility) rsrctype(fac)

Check Contents

From the ISPF Command Shell enter:
ACF
SET CONTROL(GSO)
SHOW CLASMAP

If the CLASMAP DEFINITIONS list does not include entries for the FACILITY, SURROGAT, and UNIXPRIV resource classes, this is a finding.
NOTE: The default TYPE CODE values should be FAC, SUR, and UNI.

Vulnerability Number

V-223436

Documentable

False

Rule Version

ACF2-ES-000150

Severity Override Guidance

From the ISPF Command Shell enter:
ACF
SET CONTROL(GSO)
SHOW CLASMAP

If the CLASMAP DEFINITIONS list does not include entries for the FACILITY, SURROGAT, and UNIXPRIV resource classes, this is a finding.
NOTE: The default TYPE CODE values should be FAC, SUR, and UNI.

Check Content Reference

M

Target Key

4100

Comments