Irwin M. Deutsch wrote:

Hi,

Our auditor has asked  why have not protected the command to 'stop' racf.
Neither I nor our MVS gurus know of such an animal. I found some STOP for
RRSF in System Command manual, but that's just some part of RACF.

Any ideas on what our auditor is talking about?

Idea #1.
Auditor has no idea also.

Idea #2.
STOP RACF address space.
Nothing related to security (holes).
RACF A/S is optional, can be started or stopped during normal operations.
This command can be protected using (AFAIR) RACF.STOP profile in OPERCMD class.

Idea #3.
He means stop RACF.
No such stop.

Idea #4.
He means RVARY INACTIVE.
RVARY command is *not protected* by any profile, it is protected by password. After RVARY WTOR is issued, operator have to reply with password or NO word.


--
Radoslaw Skorupka
Lodz, Poland

----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to [EMAIL PROTECTED] with the message: GET IBM-MAIN INFO
Search the archives at http://bama.ua.edu/archives/ibm-main.html

Reply via email to