News
Abstract
This zSecure Service Stream Enhancement (SSE) includes IBM Security zSecure Admin 3.1.1 and other updates in the zSecure 3.1.0 service stream. The zSecure 3.1.0 documentation was refreshed with all the updates related to these enhancements.
Content
- Introducing the WebUI interface for zSecure Admin.
- A new primary command SHOWLOG displays the content of the CARLa SYSPRINT listing. If a high severity message is issued in the ISPF User Interface, it will be displayed automatically.
- zSecure Compliance enhancements:
- PCI-DSS v4 support AU.R: Previously supported PCI-DSS 3.2 controls are converted to PCI-DSS v4 variant. All PCI-DSS v4 controls use multi-standard syntax.
- Added CIS IBM Db2 for z/OS Benchmark v1.0.0 standard. This standard is only available with a Z Security and Compliance Center licence.
- Further automation of RACF CIS IBM z/OS RACF Benchmark standard. Automation for the following controls is added:
CIS ID CARLa member Control Description 2.1.4 CKAHR214 Ensure that the ICHDSM00 program is protected 2.1.9 CKAHR219 Ensure the RACF remote sharing facility files are protected 2.1.11 CKAHR21B Ensure that RACF remote sharing connections use the TCP/IP 2.4.10 CKAHR24A Ensure that MCS consoles access is protected through CONSOLE class profile 2.4.5 CKAHR245 Ensure that started tasks requiring exceptional access rights use the TRUSTED attribute 6.2.10 CKAHR62A Ensure FTP Control cards are stored in a secure PDS file 6.2.2 CKAHR622 Ensure startup parameters for the FTP daemon do not allow ANONYMOUS or INACTIVE keywords 6.6.4 CKAHR664 Ensure AT-TLS protection is enabled for the TN3270 Telnet server 7.1.4 CKAHR714 Ensure ICSF is configured to start during IPL 7.2.4 CKAHR724 Ensure ICSF Key Data Sets have a system backup 7.2.5 CKAHR725 Ensure ICSF Master Keys have a backup procedure 7.3.5 CKAHR735 Ensure ICSF Key Store Policy controls are enabled 7.3.6 CKAHR736 Ensure ICSF Key Datasets are protected 7.3.8 CKAHR738 Ensure ICSF operator commands are protected 8.4.1 CKAHR841 Ensure that data sets on SPOOL are encrypted as required 9.17 CKAHR9H Ensure that security commands in /etc/rc are safe - Added IBM Security zSecure for ACF2 v1.1 standard.
- Updated list of DISA STIG and CIS IBM z/OS with RACF Benchmark compliance standards available in zSecure 3.1.0.
- Newlist types:
- The new ACF2_DB2_RULE and ACF2_DB2_RULELINE newlists are used for the processing of ACF2 Option for DB2 rules. *)
- The new DB2_COLUMN newlist type reports on table columns, which enables auditing the Db2 columns. *)
- New fields for ACF2_LID.
- New fields for SMF 1154 records, subtype 49 and SMF 42-6 records.
- New field ACCESS_IS_OWNER for ACCESS newlist type.
- Improved serialization when reading the live RACF database; exclusively enqueue the RACF database to ensure an unload has no structural errors caused by concurrent updates.
- User Interface enhancements:
- Db2 Access control (RE.D.AC).
- Db2 Permission/Mask (RE.D.CT).
- Db2 Table columns (RE.D.TC). *)
- zSecure Command Verifier enhancements:
- New policy profile for NOCSDATA parameter for User, Dataset, Group, and General Resource profiles.
- Additional validation for policy profile C4R.*.ACL./GROUP.*.**
- Command Verifier to invoke REXX or CLIST via =PSTCMD profiles.
- Enhanced Audit Trail data insert.
- Allows self-grant where user ID is HLQ of profile.
- zSecure Alert includes report on SMF record statistics.
- Miscellaneous user interface enhancements:
- AU.R support for PCI-DSS v4.
- Monitoring End-to-End access in EV; this allows reporting of all SMF records with the same UnitOfWorkId or TrackingToken across multiple environments.
- Additional values for certificate signing algorithm and ICSF key attributes.
*) This function is available only if your organization has a license for Z Security and Compliance Center.
The zSecure 3.1.0 documentation was updated for this Service Stream Enhancement (SSE). Each zSecure main topic includes a PDF file and HTML pages. If you would rather receive a single zip file with all the PDF files, you can download the following zip file: zSecure 310 doc SSE-Oct2024.zip
Related Information
OA66990 (HCKR310) - zSecure 3.1.0 SSE (October 2024) - Base
OA67129 (HCKR310): zSecure 3.1.0 SSE (October 2024) - Base
OA66991 (JC2A310) - zSecure for ACF2
OA66992 (JCKC310) - IBM Z Security and Compliance Center (ZSCC)
OA66993 (HC4R310): zSecure Command Verifier (base)
OA66994 (JC4R310): zSecure Command Verifier
zSecure Compliance Standards (OA66990 - RACF/Top Secret, OA66991- ACF2, OA66992…
Announcement: IBM Security zSecure Admin 3.1.1 adds graphical interface
Blog by Jeroen Tiggelman, IBM Security zSecure Release Manager
Was this topic helpful?
Document Information
Modified date:
03 February 2025
UID
ibm17173741