UCF STIG Viewer Logo

CL/SuperSession's Resouce Class is not defined or active in the ACP.


Overview

Finding ID Version Rule ID IA Controls Severity
V-224656 ZCLST038 SV-224656r855143_rule Medium
Description
Failure to use a robust ACP to control a product could potentially compromise the integrity and availability of the MVS operating system and user data.
STIG Date
z/OS CL/SuperSession for TSS Security Technical Implementation Guide 2022-10-10

Details

Check Text ( C-26339r519785_chk )
a) Refer to the following report produced by the TSS Data Collection:

- TSSCMDS.RPT(#RDT)

b) If the resource class of KLS is defined, there is NO FINDING.

c) If the resource class of KLS is not defined, this is a FINDING.
Fix Text (F-26327r519786_fix)
Add the resource KLS to the TOP SECRET RDT using the following TSS command example:

TSS ADD(RDT) RESCLASS(KLS) RESCODE(xx)

(where xx is an unused hex value)