CL/SuperSession's Resouce Class is not defined or active in the ACP.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-224656ZCLST038SV-224656r1145883_ruleCCI-000336medium
Description
Failure to use a robust ACP to control a product could potentially compromise the integrity and availability of the MVS operating system and user data.
STIGDate
z/OS CL/SuperSession for TSS Security Technical Implementation Guide2025-09-28

Related Frameworks

2 paths across 2 frameworks
NIST 800-531 mapping
  • DISA · V7R2 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI1 mapping
CCI-000336
1.00
  • DISA · V7R2 · disa_xccdf · related

Details

Check Text (C-224656r1145883_chk)

Refer to the following report produced by the TSS Data Collection: - TSSCMDS.RPT(#RDT). If the resource class of KLS is defined in the Resource Definition Table (RDT), this is not a finding.

Fix Text (F-26327r1145882_fix)

Add the resource KLS to the TOP SECRET RDT using the following TSS command example: TSS ADD(RDT) RESCLASS(KLS) RESCODE(xx) (where xx is an unused hex value)