Auditing, privileged access and security operations
Security is proven by evidence. The ESM writes SMF records of who did what, auditors check them against policy, and the most powerful identities are controlled tightly. When something looks wrong, security operations follow an incident process that protects both systems and evidence.
SMF: the security evidence
RACF writes SMF type 80 records for security events: failed and, if requested, successful accesses, changes to profiles, and commands issued by privileged users. ACF2 and Top Secret write their own SMF records. Other components add their own evidence, so a complete picture combines several record types.
| Want to see | How it is usually captured (RACF terms) |
|---|---|
| Access failures | Logged by default as violations |
| Successful reads of a sensitive dataset | AUDIT option on the profile, such as AUDIT(ALL(READ)) |
| All actions by one user | UAUDIT on the user |
| Commands by SPECIAL users | SETROPTS SAUDIT |
| Class-wide logging | SETROPTS LOGOPTIONS and AUDIT(class) |
Logging everything is not free: SMF volume grows and real alerts get lost in noise. Audit settings are agreed with the audit and compliance teams and reviewed.
From records to reports
IBM's IRRADU00 utility unloads RACF SMF records into a readable format. Many sites also use security products such as IBM zSecure, BMC AMI Security or Broadcom tools for ACF2 and Top Secret to analyse events and forward them to a SIEM such as Splunk or IBM QRadar, so mainframe events appear alongside the rest of the enterprise. Product choice depends on the site.
Compliance
Banks and insurers must show regulators and auditors that access is controlled. Standards such as PCI DSS and internal controls derived from laws like SOX lead to regular recertification of access, evidence that privileged actions are logged, and proof of segregation of duties. Mainframe controls are tested the same way as any other platform's.
Privileged access
A few attributes and authorities can bypass normal checks. Treat them as privileged access.
- SPECIAL: can change any RACF profile. OPERATIONS: broad dataset access. AUDITOR: can set audit options and read audit data. Group-level versions apply within a group.
- UID 0 or BPX.SUPERUSER in z/OS UNIX.
- Update access to APF-authorised libraries: a program placed there can bypass system integrity.
- Powerful FACILITY, OPERCMDS and SURROGAT profiles, and the equivalents in ACF2 and Top Secret.
Good practice: very few permanent holders, named personal ids rather than shared ones, break-glass (firecall) ids for emergencies whose use is logged and reviewed, and regular recertification. Multi-factor authentication for privileged users is now common.
Security operations day to day
- Monitor alerts and repeated violations such as ICH408I messages and revoked ids.
- Handle access requests through approved workflows, granting groups rather than individuals.
- Run periodic reviews: dormant users, excessive access, privileged holders.
- Respond to incidents: detect, contain, preserve evidence, recover, review.
- Keep certificates, keys and passwords for functional ids under managed rotation.
Which SMF record type does RACF write for security events?
Show a hint
It is a two-digit number.
Show the solution
RACF writes SMF type 80 records for security events.
Common mistakes
Excessive audit settings flood SMF and hide real alerts. Agree targeted settings with audit and review them.
Shared ids destroy accountability. Use personal ids with the minimum privilege and logged break-glass ids for emergencies.
Quiet fixes destroy evidence and break the incident process. Preserve SMF data and follow the runbook first.
What you will see at work
- Security analysts review SIEM alerts that include mainframe SMF events alongside other platforms.
- Auditors ask for lists of privileged users and evidence that their actions are logged.
- Access recertification campaigns ask managers to confirm or remove each person's mainframe access.
Key terms
Check your understanding.
Take this lesson's quiz and save your progress. Free.