Skip to content
Security / Governance, Risk & Compliance

IBM Security zSecure RACF and SMF Auditing

This course describes the audit problems reported by IBM® Security zSecure™ Audit. The course explains auditing the RACF® database and z/OS subsystems such as CICS, IMS and DB2. You can measure your security and z/OS settings against the security requirements of your chosen policy level. You will also learn about the Access Monitor dataset containing historical statistics of RACF access decisions. This information is used to find profiles, permissions or connections that are unused and can be removed from the RACF database. In addition, you will learn how to review general SMF and RACF audit settings. This course explains how to use and interpret predefined SMF reports and how to create custom SMF reports. Finally, the functions of analyzing library status and changes and the sequential data set are explained.

Issues

  • Describe and explain the flow of calling security from z/OS and resource managers to RACF

  • Perform an audit analysis of user IDs and passwords

  • Audit confidential user IDs and z/OS resources and create audit reports on those authorized to define RACF profiles

  • Create audit reports for CICS, IMS and DB2 subsystems

  • Review system-wide audit settings, select and process predefined SMF reports, and define custom SMF reports

  • Using Access Monitor reports to clean up the RACF database

  • Audit changes to system confidential libraries and sequential data sets

Who is this training for?

The training is designed for RACF security administrators and auditors who are responsible for administering RACF, generating audit reports and auditing RACF and z/OS security
RACF and z/OS compliance specialists will also benefit from attending this training

Prerequisites

  • Basic knowledge and experience with z/OS, RACF and zSecure platform
  • Ability to log in to TSO and use ISPF panels
  • IBM Security zSecure Admin Basic Administration and Reporting TK263
  • Basics of RACF z/OS ES19G administration
  • Successful administration of the RACF BE87G

Training program

01

Day 1: RACF auditing — users, resources, subsystems

  • Introduction to RACF auditing — security call flows from z/OS and resource managers to RACF
  • Auditing user IDs and passwords — privilege analysis, password policies, special accounts
  • Auditing sensitive resources — authorization reports, who can define RACF profiles
  • Subsystem auditing — generating audit reports for CICS, IMS and DB2
  • Exercises: identifying excessive privileges and sensitive accounts
02

Day 2: SMF, Access Monitor, library analysis

  • SMF auditing — review of system audit settings, predefined SMF reports
  • Creating custom SMF reports — defining criteria, filtering events
  • Access Monitor and RACF-Offline — analyzing historical access decisions, identifying unused profiles
  • RACF database cleanup — removing unnecessary privileges and connections based on Access Monitor data
  • Library and sequential dataset analysis — monitoring changes in system-critical libraries

Delivery Methods

Online

  • Convenience of participating from anywhere
  • Interactive live sessions with trainer
  • Materials available for 30 days
  • No travel costs

On-site

  • Direct contact with trainer and group
  • Intensive hands-on workshops
  • Networking with other participants
  • Full focus on learning

Frequently asked questions

What are the prerequisites for this training?

For IBM Security zSecure RACF and SMF Auditing we recommend: Basic knowledge and experience with z/OS, RACF and zSecure platform; Ability to log in to TSO and use ISPF panels; IBM Security zSecure Admin Basic Administration and Reporting TK263.

What is the format and duration of this training?

The training lasts 2 days and is available in online and on-site format. Sessions run from 9:00 AM to 4:00 PM. We can also customize the schedule to fit your team's needs.

Who is this training designed for?

This training is designed for: The training is designed for RACF security administrators and auditors who are responsible for administering RACF, generating audit reports and auditing RACF and z/OS security; RACF and z/OS compliance specialists will also benefit from attending this training.

Adrian Kwiatkowski
Adrian Kwiatkowski Opiekun szkolenia

Request a quote

Funding Options

Check funding options for your company

Up to 80%

Development Services Database

Up to 80% funding for SMEs from EU funds

Check availability
Up to 100%

National Training Fund

Up to 100% funding for employers

Learn more

Trusted by

We train teams at Poland's largest companies

ING Bank - EITT client
mBank - EITT client
PKO Bank Polski - EITT client
PZU - EITT client
Allianz - EITT client
T-Mobile - EITT client
KGHM - EITT client
PGE - EITT client
IKEA - EITT client
InPost - EITT client
Leroy Merlin - EITT client
ZUS - EITT client

Interested in this training?

Contact us - we'll prepare an offer tailored to your organization's needs.

500+ experts
2500+ trainings available
ISO 9001 quality certified
Request Training
Call us +48 22 487 84 90