RACF Users' News # 51

Dec., 1999 Newsletter

Issue No. 51


RACF (part of OS/390 Security Server) is a trademark of IBM. This newsletter is not affiliated with IBM in any way.

More Name Changes From IBM

IBM has changed the name of RACF once again. For a while we thought the name was "OS/390 Security Server", but this is really the name of the package which includes RACF, the Firewall, and several other tools. IBM has now changed the name to be "Secureway" for at least the month of January. Remember how cleverly IBM named UNIX when they put it onto the mainframe. "OMVS" sure doesn't sound like UNIX. But neither does the prefix "BPX" which is used for UNIX parmlib members and manuals. But then IBM changed the name from "OMVS" to "UNIX System Services" which is abbreviated "USS", not to be confused with the VTAM "Unformatted System Services". Did you ever have an English teacher (or a corporate boss) who kept marking up your papers, no matter what you wrote. And then you finally figured out that if you saved your original draft and turned it in again as the fifth or sixth, it might be accepted? Who would like to bet that the name of RACF will some day come around again, either as the "brand new" name for IBM's mainframe security software, or as a table in VTAM?

NEW YORK RUG Meeting Dates

On Wednesdays, from 1 to 5 PM: this quarter on January 12, 2000. The following meeting will be April 12, 2000. Mark your calendars now. See inside for details.

BALTIMORE/WASHINGTON RUG

Meeting Dates

On Thurdays, from 9AM to Noon: But there will be no meeting this quarter. The next meeting is scheduled for April 13, 2000. Mark your calendars now. See inside for details.

-------------------------------------------

More Change in the RACF Software Industry

Technologic Software has acquired LT Technologies' SSSR (Security Server SMF Reporting). Call Bill Tomlinson or Dick Kielb at (949) 509-5000 for more info. We understand that: "SSSR provides 32 pre- packaged RACF reports organized for use on daily, weekly, and monthly schedules, and the convenience of regular, standard analysis and the ability to quickly focus on trouble areas. On demand analysis gives you the ability to drill down into any security issue and provide instant insight into any problem or request."

Technologic Software has another product called In-Compliance, which provides "a new Web interface tool to RACF that allows administrators and auditors to analyze, compare, and set thresholds on over 200 standards/rules/policy categories they have established. The tool will notify you via electronic communication (fax, pager, e-mail) when any of the compliance and tolerance levels you set deviates."

More on UNIXPRIV Resource Class Rules

Here is a more complete list of rules in this class:

(These all require READ access except as noted)

Fifteen Minute Project to Improve Your RACF

Here's a basic check to see if your RACF implementation is as comprehensive as it should be (according to our highly biased, but completely correct opinion):

Are All Paths Into Your System Controlled by RACF?

Are All Datasets Protected by RACF?

Are All Appropriate Resource Protected by RACF?

Do You Have a Plan in Place to Address These Issues?

This checklist helps you to determine whether your RACF implementation is comprehensive, and to some degree whether your RACF implementation is managed. In a future issue, we will provide a separate checklist to help you determine the quality of your RACF implementation, as opposed to its completeness. WARNING: Don't let your auditor see any of these checklists.

Critical Performance Tips From George Fogg on the RACF List Server:

Thanks yet again, George.

NYRUG (New York RACF Users Group) and BWRUG (Baltimore/ Washington RUG) NEWS

NYRUG: At Our Next Meeting

Our next meeting will be at Prudential Securities. Our speakers will be Hayim Sokolsky of Vanguard on the subject: "How to Secure SDSF with RACF" and Stu Henderson on the topic: "How to Break Into an OS/390 System". As always, we will have a question and answer session with some of the keenest RACF minds in the State to answer questions.

Time: Wednesday, January, 12, 2000 from 1PM until it's too late to go back to the office.

Place: Prudential Securities at One Seaport Plaza, aka 199 Water Street, (on Water Street between Fulton and John Streets in downtown Manhattan in the Peking Room on the 9th Floor Here are some useful subway stops: ---IRT 2 or 3: Fulton Street stop, proceed east about 2 short blocks; ---IND A: Broadway-Nassau Street stop, proceed east about 4 short blocks; ---IND E: Chambers Street stop (last stop), proceed east about 6 short blocks; ---Lex 4 or 5: Fulton Street stop, proceed east about 4 short blocks; ---BMT N or R: Cortlandt Street stop, proceed east about 6 short blocks. As you can see, Water Street overlooks the East River, near the Brooklyn Bridge. ============================================================== BWRUG (Baltimore/Washington RUG):

The BWRUG will not meet this quarter. Our next meeting is scheduled for April 13, 2000.

Wherever You Live or Work:

Why not see if your organization can host a meeting for your local RUG?

Permanently Interesting Products Column

We have not evaluated these, but think every RACF shop should know about them.

HG RACF and Security Training 1998 Schedule:

The Henderson Group offers its RACF and computer security/audit seminars around the country and on-site too. See the details below or call (301) 229-7187 for a free seminar catalog.


            The Henderson Group offers its RACF and computer security/audit seminars around the
country and on-site too.  See the details below or call (301) 229-7187 for a free seminar catalog.  


  1)        HG04 Effective RACF Administration ($1695)  

              Feb. 21-25,            2000 in Clearwater, FL
              Mar. 20-24,            2000 in Atlanta, GA
  (REVISED)   Oct. 23-27,             2000 in New York City
              Dec. 4-8,              2000 in Bethesda, MD (near Washington, DC)


  2)        HG05 Advanced RACF Administration  ($1185)

              Feb. 16-18,            2000 in Clearwater, FL
              May  22-24,            2000 in Denver, CO
              Oct. 4-6,              2000 in Bethesda, MD (near Washington, DC)


  3)        HG17 How to Be an Effective OS/390 (MVS) Data Security Officer) 
            (covers CICS, VTAM, DB2, JES, and other security along with MVS 
            security, SAF, and OS/390)             ($1190) 

              Feb. 2-4,              2000 in Atlanta, GA         
              Apl. 5-7,              2000 in New York City 
              Nov. 8-10,             2000 in Bethesda, MD (near Washington, DC)


  4)        HG40 Mastering Windows 2000 (NT) Security   (Windows 2000 is the 
            new name for Windows NT Release 5, or NT5; this class covers NT4 
            security as well as Windows 2000 security) ($1195)

  (REVISED)   May 31-June 2          2000 in New York City 
              Sept. 27-29,           2000 in Bethesda, MD (near Washington, DC)

RACF User Services (Newsletter Subscriptions / Key Phone Numbers / Addresses)

RACF List Server on the Internet

To join, send E-mail to the administrator for the server. (Don't send it to the server itself or your request will be routed to every subscriber.) For example, if your name is John Smith and you want to subscribe, then send this E-mail:

subscribe racf-l john smith

to the address: listserv@listserv.uga.edu

The reply will include directions on how to get info such as a list of all subscribers, an index to previous comments, and a command summary.

Other Internet places: