AppliedSecurity32 min
Mainframe security engineering
The next step after RACF basics: how SAF and the three security managers compare, how certificates, AT-TLS and pervasive encryption protect data, and how auditing, privileged access control and incident handling work in a regulated shop.
What you will be able to do
- Compare RACF, ACF2 and Top Secret and explain the role of SAF
- Describe keyrings, RACDCERT, AT-TLS and the Policy Agent at concept level
- Explain pervasive encryption, ICSF and key label access
- Use SMF type 80 auditing, privileged access controls and an incident process
Lessons
- SAF and the three security managersz/OS products do not check security themselves. They ask SAF, which passes the question to the installed external security manager: RACF, ACF2 or Top Secret.
- Certificates, TLS and encryptionData on the mainframe is protected in transit with TLS and at rest with encryption.
- Auditing, privileged access and security operationsSecurity is proven by evidence. The ESM writes SMF records of who did what, auditors check them against policy, and the most powerful identities are controlled tightly.
Track your progress and earn a certificate.
Free account, 15 quiz questions for this subject.