Information Security and IT Audit Articles
from the Henderson Group
This page is:
ARTICLES

Quick Links:

HOME PAGE

CONTACT US

INFOSEC TRAINING

IT AUDIT TRAINING

RACF USER NEWS (Describes next NYRUG Meeting

NEWSLETTERS AND USER GROUPS

ARTICLES

PRIVACY STATEMENT

ABOUT US

OTHER INFO SOURCES

ARTICLES FOR SECURITY AND AUDIT PROFESSIONALS
The following articles are available for your review, printing, or downloading. You may select them by clicking on the description below.

How to Secure Mainframe FTP ( in the Dec-Jan 2008 ZJournal)
includes several articles including how to secure FTP on the mainframe

21 Things You Didn't Use to Know About RACF, a Technical Update for Auditors
describes 21 items auditors should be familiar with in order to audit RACF security on an MVS or z/OS system

Full Tape Security from Security Software and Tape Mgt. Software)
describes how to get full security for tape datasets by using both security software and tape management software

How to Break Into z/OS Systems (PDF Handout from a Presentation)
describes techniques for breaking into MVS (z/OS or OS/390) systems and how to protect against them

Interpreting Output from the RACF SETR LIST Command
explains the output from this command and recommends how you might want to set its options

Interpreting Output from the RACF DSMON Utility
explains the 11 reports provided by this utility and recommends how you might want to set its option for your organization.

The SERVAUTH Resource Class
describes the SERVAUTH resource class in RACF (IBM's security software for mainframe computers), which is used to control connections to TCP/IP networks.

How to Write a Security Policy
shows you practical considerations for writing a computer security policy for your organization.

Trends in MVS Security
shows you the security history and trends in the MVS operating system and helps you to project from them.

How to Audit Windows NT Security
shows you how Windows NT security works, and how to go about auditing it.

Audit Report Guidelines
describes guidelines for auditors to consider to make their reports more effective.


"Created a clearer picture in my mind on how to go about measuring and improving RACF effectiveness."

--- Joseph Gravagna, Golden Rule Insurance

"I would recommend this class for anyone who wants to learn the correct way to administer RACF security.
"
--- Anthony Cleveland, TECO Energy