Security facilities for DB/DC and DCCTL resources
The following table summarizes the resources you can protect, the types of security that you can use to protect the resources, and the security facilities that you can use to implement each type of security.
When choosing which security facilities to use, also consider your installation's security standards and operating procedures.
| Resource | Type of security | Security facility |
|---|---|---|
| IMS control region and online system | Extended resource protection (using APPL resource class) | RACF® |
| System data set | z/OS® password protection | z/OS |
| Data set protection (VSAM) | RACF | |
| Database | Segment sensitivity | PSBGEN RACF |
| Field sensitivity | PSBGEN RACF | |
| Password security (for the /LOCK and /UNLOCK commands) | RACF | |
| PTERM | Signon verification security | RACF with exit routine |
| Terminal-user security | RACF | |
| Password security (for the /LOCK and /UNLOCK commands) | RACF | |
| LTERM | Password security (for the /LOCK and /UNLOCK commands) | RACF |
| Resource Access Security | RACF | |
| Terminal defined with ETO | Signon verification security | RACF and exit routine |
| Input access security | RACF and exit routine | |
| LU 6.2 inbound and IMS-managed outbound conversations | Allocate verification security | RACF and exit routine |
| Input access security | RACF and exit routine | |
| PSB | Resource Access Security | RACF |
| APSB SAF security | RACF1 | |
| Transaction | Input access security | RACF |
| Output access security | System definition | |
| Resource Access Security | RACF | |
| Password security (for the /LOCK and /UNLOCK commands) | RACF | |
| Command | Default security | System definition |
| Transaction command security for automated operator (AO) commands | RACF or Command Authorization exit routine | |
| Input access security | RACF | |
| type-2 command security | RACF | |
| DBRC command authorization2 | RACF or exit routine | |
| Type-1 Automated Operator Interface applications | Transaction command security | RACF or Command Authorization exit routine |
| Type-2 Automated Operator Interface applications | Transaction command security | RACF or Command Authorization exit routine |
| Online application program | Password security (for the /LOCK and /UNLOCK commands) | RACF |
| Extended resource protection (using APPL keyword) | RACF | |
| Dependent region | APSB SAF security | RACF |
| Resource Access Security | RACF |
Notes:
- Using RACF to secure APSBs applies only to CPI-C driven applications and ODBA applications.
- DBRC command authorization is an additional command security option that applies only to DBRC commands. DBRC commands are also subject to any other command security options that are active in the IMS system.