Call : (+91) 968636 4243
Mail : info@EncartaLabs.com
EncartaLabs

IBM Security zSecure RACF and SMF Auditing

( Duration: 2 Days )

The IBM Security zSecure RACF and SMF Auditing training course explains how to audit the content of Resource Access Control Facility (RACF) database and z/OS system. You can measure the current security settings against the security requirements of a selected policy level. In addition, you learn about an Access Monitor data set that contains statistics about all RACF decisions taken. This information is helpful for finding profiles, permissions, or connections that are not used and can, therefore, be removed from the RACF database. Furthermore, you learn how to review the current general Service Management Framework (SMF) and RACF audit settings. This course explains how to use and interpret the pre-defined SMF audit reports, and how to create own customized SMF reports. Finally, the concepts of the Library status and change analysis functions are explained and demonstrated.

By attending IBM Security zSecure RACF and SMF Auditing workshop, delegates will learn to:

  • Describe the flow of a security call from Resource Managers to RACF
  • Perform user ID and password audit analysis
  • Use the audit functions to report on sensitive user IDs and z/OS resources
  • Create audit reports on key RACF and z/OS system tables
  • Create audit reports for the CICS, IMS, and DB2 subsystems
  • Review the system-wide Audit settings
  • Select and process predefined SMF reports
  • Define custom SMF reports
  • Utilize the Access Monitor reports
  • Clean up the RACF database
  • Audit changes to system-sensitive libraries

  • A basic knowledge of, and experience with, the z/OS platform, RACF, and zSecure
  • The ability to log on to TSO and use ISPF panels
  • Basic RACF and IBM Security zSecure education is assumed

This IBM Security zSecure RACF and SMF Auditing class is targeted for RACF security administrators and auditors.

COURSE AGENDA

1

Introduction to RACF auditing

  • List the RACF resources that need to be audited
  • Generate and interpret an audit concerns report
  • Identify all the profiles owned by a particular user
  • Identify the users authorized to maintain RACF application segments
2

Audit users and passwords

  • Generate and interpret user reports
  • Identify last logon and password aging
  • Identify users with system-wide authorities
  • Identify users with group specific authorities
  • Generate a report of trusted users
3

Audit resources

  • Identify sensitive profiles and the users who can modify them
  • Identify users who can create profiles of various types
  • Audit started tasks and programs
4

Audit subsystems

  • Generate audit reports about CICS regions, transactions, and programs
  • Generate audit reports about IMS regions, transactions, and program specification blocks
  • Generate audit report about DB2 region
5

Generate SMF audit reports

  • Explain the concepts of SMF auditing
  • Report which events are logged in SMF
  • Select events logged in SMF using ISPF interface
  • Report SMF events with predefined reports
  • Create customized SMF reports
6

Access Monitor and RACF Offline

  • Explain the Access Monitor functions and reports
  • Generate access summary overview reports
  • Compare historic access events against current RACF database definitions
  • Analyze permit, connect, profile, member, and global access entry usage
  • Remove unused profiles and authorizations
  • Use the RACF Offline component combined with Access Monitor
7

Library Analysis

  • Track changes that occur in z/OS system sensitive libraries

Encarta Labs Advantage

  • One Stop Corporate Training Solution Providers for over 6,000 various courses on a variety of subjects
  • All courses are delivered by Industry Veterans
  • Get jumpstarted from newbie to production ready in a matter of few days
  • Trained more than 50,000 Corporate executives across the Globe
  • All our trainings are conducted in workshop mode with more focus on hands-on sessions

View our other course offerings by visiting https://www.encartalabs.com/course-catalogue-all.php

Contact us for delivering this course as a public/open-house workshop/online training for a group of 10+ candidates.

Top
Notice
X