Home » IBM » IBM Software » Rational » Enhanced Access Control for SCLM for z%3AOS
IBM

Enhanced Access Control for SCLM for z%3AOS

IBM Enhanced Access Control for Software Configuration and Library Manager (SCLM) for z/OS® provides additional control over access to SCLM-managed libraries.

Improve access control of your SCLM resources

Enhanced Access Control for SCLM augments Resource Access Control Facilty (RACF®) controls. After normal RACF security controls are applied, you can use Enhanced Access Control for SCLM to grant access when a specific set of applications such as SCLM are used.

The applications can even define various subfunctions of SCLM, for example, an SCLM Promote may be allowed access whereas an SCLM Edit may be denied access.

Without Enhanced Access Control for SCLM, SCLM users operating in a RACF environment must be granted UPDATE access to manipulate SCLM-managed data sets. Otherwise, they receive RACF data set violations when performing various SCLM functions.

However, the UPDATE access applies even if the data set is accessed using facilities other than SCLM, thus allowing access to potential users from facilities other than SCLM.

Prevent unintended changes to SCLM managed data sets

The central concept of Enhanced Access Control for SCLM is that access to SCLM resources is provided when SCLM programs are used. This avoids the potential for unexpected changes to SCLM data sets resulting from updates using non-SCLM programs.

The SCLM programs are described using applications. The data sets to be controlled and their access rules are described using Profiles.

Provide additional levels of access control

Currently, access to SCLM-controlled data is restricted, based on RACF or other security package and is done on a data set basis.

Enhanced Access Control for SCLM works with IBM RACF to allow you to further restrict access to SCLM data so that it can only be accessed using the SCLM family of products.

It also allows you to restrict access from within the SCLM family based on function, so you can decide which users should have access to which SCLM functions.

When Enhanced Access Control for SCLM is active, it monitors RACF data set violations. If a violation occurs for a data set managed according to the Enhanced Access Control for SCLM profiles, then the defined access rules are used to assign access privileges. If sufficient access privilege is not defined, then a RACF data set violation occurs.

Like RACF, Enhanced Access Control for SCLM has its own rules database that describes the conditions under which access is granted. These are contained in the Rule File, a VSAM KSDS that is administered through the ISPF Dialog.

From these online panels, the Enhanced Access Control for SCLM administrator can:

  • Define the data sets or generic RACF data set profiles to be controlled

  • Define SCLM and its subfunctions as applications

  • Define the users granted access privileges to a profile through an application

  • View violation records collected by Enhanced Access Control for SCLM

All products within the Rational category

Contact us today for more information

  • or call: 0345 230 1055
  • * Required fields
  • Nature of your Enquiry (any additional details)
  • I have read & agree to the Privacy Policy *
 

Featured resources for Enhanced Access Control for SCLM for z%3AOS


Latest News

Oracle Fighting to Keep Linux Open and Free 30/08/2023

Oracle has just released a statement by...

ACARDIA LIMITED 12th Floor, Ocean House, The Ring, Bracknell, Berkshire RG12 1AX. United Kingdom.