STIGQter STIGQter: STIG Summary: IBM z/OS ACF2 Security Technical Implementation Guide Version: 8 Release: 2 Benchmark Date: 23 Apr 2021:

IBM z/OS DFMSM resource class(es)must be defined to the GSO SAFDEF record in accordance with security requirements.

DISA Rule

SV-223596r533198_rule

Vulnerability Number

V-223596

Group Title

SRG-OS-000080-GPOS-00048

Rule Version

ACF2-SM-000040

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Define the GSO SAFDEF record with the following definitions:

FACILITY
PROGRAM

Ensure both resource classes above are defined.

Example:
SHOW SAFDEF

SET C(GSO)
INSERT SAFDEF.FAC FUNCRET(4) FUNCRSN(0) ID(FACILITY) MODE(GLOBAL) RACROUTE(REQUEST=AUTH CLASS=FACILITY) RETCODE(4)

F ACF2,REFRESH(ALL)

Check Contents

From the ISPF Command Shell enter:
ACF
SET CONTROL(GSO)
SHOW SAFDEF

If both FACILITY and PROGRAM resource classes are defined, this is not a finding.

Vulnerability Number

V-223596

Documentable

False

Rule Version

ACF2-SM-000040

Severity Override Guidance

From the ISPF Command Shell enter:
ACF
SET CONTROL(GSO)
SHOW SAFDEF

If both FACILITY and PROGRAM resource classes are defined, this is not a finding.

Check Content Reference

M

Target Key

4100

Comments