Security facilities for DB/DC and DCCTL resources

The following table summarizes the resources you can protect, the types of security that you can use to protect the resources, and the security facilities that you can use to implement each type of security.

When choosing which security facilities to use, also consider your installation's security standards and operating procedures.

Table 1. DB/DC and DCCTL resources and the facilities to protect them
Resource Type of security Security facility
IMS control region and online system Extended resource protection (using APPL resource class) RACF®
System data set z/OS® password protection z/OS
Data set protection (VSAM) RACF
Database Segment sensitivity PSBGEN RACF
Field sensitivity PSBGEN RACF
Password security (for the /LOCK and /UNLOCK commands) RACF
PTERM Signon verification security RACF with exit routine
Terminal-user security RACF
Password security (for the /LOCK and /UNLOCK commands) RACF
LTERM Password security (for the /LOCK and /UNLOCK commands) RACF
Resource Access Security RACF
Terminal defined with ETO Signon verification security RACF and exit routine
Input access security RACF and exit routine
LU 6.2 inbound and IMS-managed outbound conversations Allocate verification security RACF and exit routine
Input access security RACF and exit routine
PSB Resource Access Security RACF
APSB SAF security RACF1
Transaction Input access security RACF
Output access security System definition
Resource Access Security RACF
Password security (for the /LOCK and /UNLOCK commands) RACF
Command Default security System definition
Transaction command security for automated operator (AO) commands RACF or Command Authorization exit routine
Input access security RACF
type-2 command security RACF
DBRC command authorization2 RACF or exit routine
Type-1 Automated Operator Interface applications Transaction command security RACF or Command Authorization exit routine
Type-2 Automated Operator Interface applications Transaction command security RACF or Command Authorization exit routine
Online application program Password security (for the /LOCK and /UNLOCK commands) RACF
Extended resource protection (using APPL keyword) RACF
Dependent region APSB SAF security RACF
Resource Access Security RACF
Notes:
  1. Using RACF to secure APSBs applies only to CPI-C driven applications and ODBA applications.
  2. DBRC command authorization is an additional command security option that applies only to DBRC commands. DBRC commands are also subject to any other command security options that are active in the IMS system.