STIGhubSTIGhub
STIGsRMF ControlsCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • RMF Controls
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 5 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to z/OS CL/SuperSession for RACF Security Technical Implementation Guide

V-224467

CAT II (Medium)

CL/SuperSessions Resouce Class must be defined or active in the ACP.

Rule ID

SV-224467r1144737_rule

STIG

z/OS CL/SuperSession for RACF Security Technical Implementation Guide

Version

V7R2

CCIs

CCI-000336CCI-002358

Discussion

Failure to use a robust ACP to control a product could compromise the integrity and availability of the MVS operating system and user data.

Check Content

Refer to the following report produced by the RACF Data Collection:

- RACFCMDS.RPT(SETROPTS).

Automated Analysis (Currently there is no automation for version 3 of CL/SuperSession) 
Refer to the following report produced by the RACF Data Collection:

- PDI(ZCLSR038).

If the CL/SuperSession resource class(es) is (are) active, this is not a finding.

Fix Text

Ensure that the CL/SuperSession Resource Class(es) is (are) active. The SYS3.OMEGAMON.qualifier.RLSPARM(KLKINNAM) member for Version 3 of CL/Supersession or the SYS3.OMEGAMON.qualifier.RLSPARM(KLVINNAM) member for version 2 of CL/Supersession contains a "CLASSES=" entry, this entry identifies the member that contains the "VGWAPLST EXTERNAL=" entry. The "VGWAPLST EXTERNAL=" entry identifies the resource class that is used by CL/SuperSession and this resource class will be active. Current guidance identifies that APPL is the resource class identified in the above location.

Use the following commands as an example:

SETROPTS CLASSACT(APPL)