Protect a user data set with RACF



All about SAF, RACF, encryption, Firewall, Risk assessment and integrity concepts

Protect a user data set with RACF

Postby XY09 » Sun Apr 22, 2012 10:37 pm

Hello Team,

I want to protect a user data set with RACF without being system-special authority. Please help me.

Thanks,
xy09.
XY09
 
Posts: 25
Joined: Mon Apr 26, 2010 9:19 am
Has thanked: 0 time
Been thanked: 0 time

Re: Protect a user data set with RACF

Postby Robert Sample » Sun Apr 22, 2012 10:55 pm

Contact your site security person. If you don't have the authority to issue RACF commands, you need to get that person to issue the commands for you.
Robert Sample
Global moderator
 
Posts: 3720
Joined: Sat Dec 19, 2009 8:32 pm
Location: Dubuque, Iowa, USA
Has thanked: 1 time
Been thanked: 279 times

Re: Protect a user data set with RACF

Postby steve-myers » Mon Apr 23, 2012 12:42 am

As Mr. Sample says, even if you can issue the RACF commands, there are so many options and ways to do this you are much better off getting assistance from the "pros." Hopefully they will do things the correct way for your site and set up the protection the way you want it done.
steve-myers
Global moderator
 
Posts: 2105
Joined: Thu Jun 03, 2010 6:21 pm
Has thanked: 4 times
Been thanked: 243 times

Re: Protect a user data set with RACF

Postby jaggz » Tue Apr 24, 2012 8:05 am

Dear XY09,

If not System Special can you please try having group special(Incase if the intended user is under your default group). You can issue ADDSD to protect your dataset but this access to be in effect then the RACF system programmers have to issue SETR GENERC(DATASET) REFR.
User avatar
jaggz
 
Posts: 356
Joined: Fri Jul 23, 2010 8:51 pm
Has thanked: 8 times
Been thanked: 5 times

Re: Protect a user data set with RACF

Postby enrico-sorichetti » Tue Apr 24, 2012 11:17 am

if the TS had had the need to know/do then the TS would not have had the need to ask
the setup would already have been done by the security support group
denying on Your/his/her access to datasets without the proper authorizations is usually cause for lawful termination !

I wonder why so many times some people just look at the lowly technicalities and completely
disregard/forget the organization/legal implications :geek:
cheers
enrico
When I tell somebody to RTFM or STFW I usually have the page open in another tab/window of my browser,
so that I am sure that the information requested can be reached with a very small effort
enrico-sorichetti
Global moderator
 
Posts: 3006
Joined: Fri Apr 18, 2008 11:25 pm
Has thanked: 0 time
Been thanked: 165 times

Re: Protect a user data set with RACF

Postby Robert Sample » Tue Apr 24, 2012 2:37 pm

I wonder why so many times some people just look at the lowly technicalities and completely
disregard/forget the organization/legal implications
Maybe because they want to protect the work they do, despite the fact that they are developing that work for their employer, on their employer's system, using their employer's resources, and getting paid by the employer?
Robert Sample
Global moderator
 
Posts: 3720
Joined: Sat Dec 19, 2009 8:32 pm
Location: Dubuque, Iowa, USA
Has thanked: 1 time
Been thanked: 279 times

Re: Protect a user data set with RACF

Postby steve-myers » Tue Apr 24, 2012 3:15 pm

jaggz wrote:Dear XY09,

If not System Special can you please try having group special(Incase if the intended user is under your default group). You can issue ADDSD to protect your dataset but this access to be in effect then the RACF system programmers have to issue SETR GENERC(DATASET) REFR.
Perhaps. However, it is extremely unlikely the TS has SETROPTS authority, and if he does the ADDSD wrong - all too likely - his user won't get the access he needs OR he'll screw up the ability of storage management to manage the data OR both.

In any event, ADDSD may not be necessary; if he's lucky some other command may be appropriate. Regardless, the TS can all too easily do it wrong. Better to go to people that hopefully will do it right the first time. That way his A is covered.
steve-myers
Global moderator
 
Posts: 2105
Joined: Thu Jun 03, 2010 6:21 pm
Has thanked: 4 times
Been thanked: 243 times

Re: Protect a user data set with RACF

Postby NicC » Tue Apr 24, 2012 5:44 pm

I wonder how an unprotected dataset got onto the system in the first place. Doesn't every site protect by default? If not - why bother!
The problem I have is that people can explain things quickly but I can only comprehend slowly.
Regards
Nic
NicC
Global moderator
 
Posts: 3025
Joined: Sun Jul 04, 2010 12:13 am
Location: Pushing up the daisies (almost)
Has thanked: 4 times
Been thanked: 136 times

Re: Protect a user data set with RACF

Postby steve-myers » Tue Apr 24, 2012 5:48 pm

It's not known whether the data is protected, or if the user does not have access. Two different issues.
steve-myers
Global moderator
 
Posts: 2105
Joined: Thu Jun 03, 2010 6:21 pm
Has thanked: 4 times
Been thanked: 243 times


Return to Mainframe Security

 


  • Related topics
    Replies
    Views
    Last post