Security options

You can secure all zRule Execution Server for z/OS resources or only specific ones. You also have the option of leaving resources unsecured. The appropriate security level depends on how you use the server.

If you plan to run your zRule Execution Server for z/OS instance in a production environment, you might want to secure some or all of your zRule Execution Server for z/OS resources. On the other hand, if you plan to run your server instance in a development or test environment, you might decide to leave resources unsecured.

Note: If you use a security product other than RACF®, bypass the following instructions and issue the equivalent security commands for your product.
Within the file system, you can secure the following resources:
  • The working directory so that only authorized user IDs can access internal data.

  • The installation directory so that only authorized user IDs can access the files needed to run the server.

Using RACF, you can secure the following resources:

  • The server resources you use to do the following tasks:
    • Issue zRule Execution Server for z/OS commands from the z/OS® console (or equivalent).
    • Sign into the Rule Execution Server console.
    • Connect to zRule Execution Server for z/OS to execute rulesets.
  • A subset of server resources. For example, you can secure access to the Rule Execution Server console only.

You also have the option of disabling security or running the server without security. The topics that follow explain how to configure support for the different options.