Mainframe Path Start learning free
Applied11 min readLesson 3 of 3

Auditing, privileged access and security operations

Security is proven by evidence. The ESM writes SMF records of who did what, auditors check them against policy, and the most powerful identities are controlled tightly. When something looks wrong, security operations follow an incident process that protects both systems and evidence.

SMF: the security evidence

RACF writes SMF type 80 records for security events: failed and, if requested, successful accesses, changes to profiles, and commands issued by privileged users. ACF2 and Top Secret write their own SMF records. Other components add their own evidence, so a complete picture combines several record types.

Want to seeHow it is usually captured (RACF terms)
Access failuresLogged by default as violations
Successful reads of a sensitive datasetAUDIT option on the profile, such as AUDIT(ALL(READ))
All actions by one userUAUDIT on the user
Commands by SPECIAL usersSETROPTS SAUDIT
Class-wide loggingSETROPTS LOGOPTIONS and AUDIT(class)

Logging everything is not free: SMF volume grows and real alerts get lost in noise. Audit settings are agreed with the audit and compliance teams and reviewed.

From records to reports

A typical security monitoring pipeline
ESMwrites SMF type 80
SMFcollected and archived
Unload or forwardIRRADU00, vendor agents
SIEM and reportsalerts, dashboards, audits

IBM's IRRADU00 utility unloads RACF SMF records into a readable format. Many sites also use security products such as IBM zSecure, BMC AMI Security or Broadcom tools for ACF2 and Top Secret to analyse events and forward them to a SIEM such as Splunk or IBM QRadar, so mainframe events appear alongside the rest of the enterprise. Product choice depends on the site.

Compliance

Banks and insurers must show regulators and auditors that access is controlled. Standards such as PCI DSS and internal controls derived from laws like SOX lead to regular recertification of access, evidence that privileged actions are logged, and proof of segregation of duties. Mainframe controls are tested the same way as any other platform's.

Privileged access

A few attributes and authorities can bypass normal checks. Treat them as privileged access.

Good practice: very few permanent holders, named personal ids rather than shared ones, break-glass (firecall) ids for emergencies whose use is logged and reviewed, and regular recertification. Multi-factor authentication for privileged users is now common.

Security operations day to day

  1. Monitor alerts and repeated violations such as ICH408I messages and revoked ids.
  2. Handle access requests through approved workflows, granting groups rather than individuals.
  3. Run periodic reviews: dormant users, excessive access, privileged holders.
  4. Respond to incidents: detect, contain, preserve evidence, recover, review.
  5. Keep certificates, keys and passwords for functional ids under managed rotation.
TRY IT YOURSELF

Which SMF record type does RACF write for security events?

Show a hint

It is a two-digit number.

Show the solution

RACF writes SMF type 80 records for security events.

Common mistakes

Logging everything

Excessive audit settings flood SMF and hide real alerts. Agree targeted settings with audit and review them.

Sharing privileged ids

Shared ids destroy accountability. Use personal ids with the minimum privilege and logged break-glass ids for emergencies.

Fixing a suspicious change before recording it

Quiet fixes destroy evidence and break the incident process. Preserve SMF data and follow the runbook first.

What you will see at work

Key terms

Check your understanding.
Take this lesson's quiz and save your progress. Free.

Take the lesson quiz
← Certificates, TLS and encryptionBack to Mainframe security engineering