z/OS DFSMShsm Managing Your Own Data
Previous topic | Next topic | Contents | Contact z/OS | Library | PDF


What is RACF protection?

z/OS DFSMShsm Managing Your Own Data
SC23-6870-00

RACF® is a program that protects data sets from unauthorized access by enabling you to define who can access your data sets and what functions they can perform on the data sets. RACF uses the information in a data set profile to determine whether a user is authorized to access the data set.

You can protect data sets with either separate RACF generic data set profiles or RACF discrete data set profiles. A RACF generic data set profile describes one or more data sets that have a similar name structure. A RACF discrete data set profile describes a specific data set on a particular volume.

DFSMShsm optionally creates a backup profile for the most recent backup version of a cataloged data set if the data set was protected with a RACF discrete profile at the time of the backup. DFSMShsm maintains only one backup profile for all backup versions of the cataloged data set. When all backup versions of the data set are scratched, the related backup profile is also scratched.

If the data set had a RACF discrete profile when backed up, profile recovery will be done if DFSMShsm finds out that the profile no longer exists when recovery is attempted.

If the data set had a RACF discrete profile when backed up and you specify NEWNAME, DFSMShsm creates a RACF discrete profile for the new name data set.

The following table lists the level of RACF resource access authority that you need to access and perform the DFSMShsm function on a RACF-protected data set. If you are not authorized to manipulate the data, DFSMShsm fails the command.

DFSMShsm
User
Command

 
DFSMShsm Function

RACF Resource Access
Authority Required

HALTERDS Changes the backup frequency and the number of backup versions kept for one or more data sets. Cannot be used on SMS-managed data sets, which are controlled by the data sets management class parameters. If used on SMS-managed data sets, the command fails and an error message is issued. ALTER
HBACKDS Creates a backup version of one or more data sets. UPDATE
HBDELETE Deletes specific backup versions of one or more data sets. ALTER
HDELETE Deletes one or more migrated data sets. ALTER
HMIGRATE Migrates one or more data sets. UPDATE
HRECALL Recalls one or more migrated data sets. EXECUTE
HRECOVER Recovers, without the NEWNAME parameter, a backup version of one or more data sets. ALTER

If profile recovery is necessary, you also need authority to create a RACF discrete profile for the recovered data set.

HRECOVER Recover, with the NEWNAME parameter, a backup version of one or more data sets. READ authority to the data set being recovered.

ALTER authority to the new name data set.

If profile recovery is necessary, you also need authority to create a RACF discrete profile for the new name data set.

For more information on the use of RACF, see z/OS Security Server RACF Security Administrator's Guide

Go to the previous page Go to the next page




Copyright IBM Corporation 1990, 2014