System parameter OSPROTECT

OSPROTECT={SYSTEM|1}

The OSPROTECT parameter specifies the operating system mitigation mode for unauthorized programs and users.

The operating system provides controls intended to help prevent unauthorized programs and users from being able to access restricted data using conventional means. Malicious or compromised unauthorized programs and users may use a security exploit to try to circumvent these controls and access restricted data. A mitigation mode determines whether the security mitigation is active or inactive. The operating system supports the following mitigation modes:

SYSTEM
Specifying SYSTEM activates the default mitigation mode intended to help prevent unauthorized programs and users from accessing restricted data using conventional means.
1
Specifying the number 1 activates mitigation mode 1, intended to help prevent unauthorized programs and users from being able to indirectly read restricted data. Mitigation mode 1 also includes the default mitigation mode (see SYSTEM). Mitigation mode 1 may have a minor impact to system performance and/or workload execution.
Value range: Not applicable.
Default: SYSTEM.
Associated parmlib member: None.