©HCCS & IBM® 2009 Stephen Linkin 1 Security On z/OS Stephen S. Linkin Houston Community College © HCCS and IBM 2009
©HCCS & IBM® 2009 Stephen Linkin 2 4/20/09 Why Security? Easy To Create And Access Computerized Information Dependent On Computer Systems Intentional/Accidental Damage System Cannot Be Compromised
©HCCS & IBM® 2009 Stephen Linkin 3 4/20/09 Security Facilities of z/OS Provide Individual And Group Authority Block Viruses, And Trojan Horses Main Threat Within Do Not Permit General TSO/ISPF Users Access To Production Systems
©HCCS & IBM® 2009 Stephen Linkin 4 4/20/09 Security Roles System Programmer Security Administrator
©HCCS & IBM® 2009 Stephen Linkin 5 4/20/09 The IBM Security Server Basic Provisions User ID and Password Restricting Functions Component List DCE Security Server LDAP Server z/OS Firewall Network Authentication Service Enterprise Identity Mapping PKI Services Resource Access Control Facility (RACF)
©HCCS & IBM® 2009 Stephen Linkin 6 4/20/09 The IBM Security Server RACF Identify And Authenticate Users Authorize Users To Access Protected Resources Log And Report Attempted Unauthorized Access Control Access To Resources Allow Applications To Use RACF Macros
©HCCS & IBM® 2009 Stephen Linkin 7 4/20/09 The IBM Security Server System Authorization Facility (SAF)
©HCCS & IBM® 2009 Stephen Linkin 8 4/20/09 Security Administration RACF Remote Sharing Facility (RRSF) RACF With Middleware
©HCCS & IBM® 2009 Stephen Linkin 9 4/20/09 Operator Console Security Multiple Console Support (MCS) AUTH keyword on CONSOLE statement for CONSOLxx LOGON keyword in DEFAULT statement and RACF commands and profiles.
©HCCS & IBM® 2009 Stephen Linkin 10 4/20/09 Integrity z/OS Has Program Integrity And Security The Authorized Program Facility (APF) Storage Protection Cross-memory Communication Authorized Programs
©HCCS & IBM® 2009 Stephen Linkin 11 4/20/09 Integrity z/OS Has Program Integrity And Security The Authorized Program Facility (APF) Storage Protection Cross-memory Communication Authorized Programs Storage Protection Cross-memory Communication
©HCCS & IBM® 2009 Stephen Linkin 12 4/20/09 Integrity z/OS Has Program Integrity And Security The Authorized Program Facility (APF) Storage Protection Cross-memory Communication Authorized Programs Storage Protection Cross-memory Communication Z/OS Firewall Technologies
©HCCS & IBM® 2009 Stephen Linkin 13 4/20/09 Summary Read The Redbook