Sunday, 20 June 2021

Auditors, compliance, and the mainframe

Mainframes have been successfully keeping organizations in business for over 50 years. Let’s just look at some statistics. Mainframes are used by 71 percent of Fortune 500 companies. They handle 90 percent of all credit card transactions. Each IBM z15 mainframe can handle 19 billion business transactions a day. And mainframes handle 68 percent of the world’s production IT workloads, yet they account for only 6 percent of IT costs.

Drilling down on those figures we find that in terms of ATMs and IMS:

  •         $7.7 trillion credit card payments (annual)
  •         29 billion ATM transactions (annual)
  •         12.6 billion transactions (daily)
  •         87% of CC Transactions done on z/OS.

With so much work taking place on a mainframe and so much money being transacted, you’d assume that auditors would be all over the mainframe. You’d probably assume that auditors would know almost as much about how mainframes work as systems programmers do. You’d think that they would want to know the tiniest of intricacies in order to assure themselves that corporations using mainframes were absolutely compliant with all the regulations that applied to them – things like the Payment Card Industry Data Security Standard (PCI DSS).

Worryingly, in many cases, auditors are put off by the complexity of mainframes and don’t know the right questions to ask. Not that I’m suggesting that organizations are committing any kind of fraud on their mainframes. What I am suggesting is that they may not be completely compliant with the regulations that apply to them.

The very nub of the problem is that the PCI DSS requires the use of file integrity monitoring (FIM) software on a computing platform, and hardly anyone using an IBM mainframe has that type of software installed. And that seems strange, bearing in mind that mainframes are used by the majority of financial institutions in the world.

Let’s look at those PCI regulations in more detail. Section 10.5.5 asks: “Is file-integrity monitoring or change-detection software used on logs to ensure that existing log data cannot be changed without generating alerts (although new data being added should not cause an alert)?”. And section 11.5 asks: “Is a change-detection mechanism (for example, file-integrity monitoring tools) deployed to detect unauthorized modification (including changes, additions, and deletions) of critical system files, configuration files, or content files?”.

Clearly, most sites aren’t compliant because they aren’t running file-integrity monitoring software on their mainframes, and yet these organizations are signing off the section 3 validation form saying that they are. And the person signing is probably the CIO, CFO, or CEO!

Many mainframe sites try to get round this issue with what they call ‘compensating controls’. The truth is that these compensating controls are basically non-existent. The next ploy used by organizations is to keep mainframes ‘out of scope’. But as shown in the figures at the start of this article, that clearly isn’t the case. And, if the auditors understood what was actually happening on the mainframe, they would be able to ask appropriate questions to show that was the case. The question they should be asking is: “If 90 percent of debit and credit transactions end up running on a mainframe, how can mainframes possibly be out of scope of a PCI Audit?”

Worryingly for many mainframe sites and their auditors is that V4.0 of DSS is due out in the next year. It’s unlikely that the rules in 3.2.1 will change. However, what is likely to change is that the enforcement and scrutiny of compensating controls will probably be greatly strengthened.

Focusing on security for a moment. On 12 May, US President Biden issued an executive order, amongst other security measures, to develop a plan to implement Zero Trust Architecture (ZTA) for Federal organizations. And zero-trust seems to be the way that security is going. NIST (The National Institute of Standards and Technology) earlier this year said: “An enterprise monitors integrity and security posture of all owned and associated assets. No asset is inherently trusted.” How do we get to ZTA on a mainframe? PWC recently published some guidelines. Item 2, on their 4-point list. says ‘File Integrity Monitoring’. That, I think, also highlights the pivotal role of file-integrity monitoring in mainframe security.

Lastly, and this is relevant because the majority of ATMs are connected to IMS running on a mainframe, there was advice from the PCI and the ATM Industry Association highlighting the need for file-integrity monitoring software on mainframes running transactions from ATMs. You may remember last October, there was an urgent bulletin from the PCI and the ATM Industry Association – the first ever bulletin issued by the two associations together, which highlights its significance – about cash-out attacks on ATMs. Thieves breached bank or card processor's security to manipulate fraud detection and took lots of cash from a number of ATMs. As we said, most ATM transactions are captured by IMS running on a mainframe. The advice given was that organizations should get file-integrity monitoring (FIM) software to combat the cash out hack.

What is file-integrity monitoring software? As its name suggests, it identifies when a file has been changed. It does this by taking a baseline copy and keeping that securely in a vault. It then checks the baseline copy against the current version at user-defined intervals and alerts when any differences are found. Obviously, lots of changes will be authorized, so, it can check against ServiceNow, BMC Helix, etc to only alert about unauthorized changes. More advanced FIM software can identify exactly what has been changed, when it was changed, and who by. And, following agreed policies, it can have the userid of the culprit suspended and the changes backed out. Ransomware attacks now corrupt backups before encrypting data. Advanced FIM software can check backups at regular intervals to identify if any unauthorized changes have been made and so help stop ransomware attacks. And it can do all this very quickly.

Putting it all together, it seems that the PCI, the US government, NIST, PWC, and others are looking at FIM as part of the answer to mainframe security. It seems that auditors need to be better prepared to ask more searching questions about mainframe compliance with agreed standards. And it seems that mainframe sites need to realize the benefits they will get from using FIM software.

Monday, 14 June 2021

How to connect to a mainframe


With the pandemic, everyone has been finding ways of working from home – or, in fact, working from anywhere. It’s not that mainframers had never worked remotely before, it’s just that recently more of them needed to do it most of the time.

Probably, the best-known way to access a mainframe is to use 3270 emulation software running on a PC. Examples of this type of software are IBM’s PComm and tn3270 from Tom Brennan Software. There are numerous others from software vendors like Rocket Software.

Some IT teams have got their IT staff to connect from their home computer to their office computer. Once they’ve logged in to their work computer, they can connect to the mainframe in the usual way using the terminal emulator installed on that computer. Connecting from their home computer to the office can be done using something like Microsoft Remote Desktop Protocol (RDP). Other organizations have used a Virtual Private Network (VPN) to allow employees to securely connect from home to their corporate network, and then access the mainframe.

These were all great ways to get connected as the pandemic and lockdown required that people be able to work from home, but now that we are, hopefully, coming out of the worst of things, it makes sense to re-evaluate our way of working and see whether there might be a better way of connecting mainframe-using employees to the mainframe.

Now is the time to ask the question, “what do users want?” as well as simply, “how can we do it?” And what users seem to want at the moment is to work from any device with a browser. It’s what they tend to do for everything they spend time on – shopping, social media, etc. So, how can we give mainframe-users a browser interface.

Virtel has been doing this for some time with Virtel Web Access (VWA). What it does is securely serve 3270 screens as standard HTML webpages over encrypted HTTPS connections to browsers. Using a browser, users see the interface that they are familiar with. The 3270 terminal emulation is a web browser.

Similarly, Rocket Software has Rocket Terminal Emulator (Web Edition), which used to be called Rocket® BlueZone Web. This, they say, delivers secure, browser-based emulation to any device, including desktops, laptops, tablets, or other mobile devices. This allows users to access mainframe applications from any browser, anywhere.

Macro 4 has Tubes, its session management software that comes with a web interface. This can web-enable mainframe applications from the user’s point of view, and employees can then access mainframes from any device with a web browser. Tubes provide a single point of entry for a user to all the applications that they’re allowed to access. And users can change from one application to another without having to log off and on again. A web-enabled session manger allows users to work on 3270 applications on any sized screen and use mouse clicks and even touch-screen commands to get work done. 3270 session manager software is available from other vendors.

A more complex solution for CICS users is provided by HostBridge Technology. They have the HostBridge JavaScript Engine (HB.js), which enables the creation of JavaScript/JSON-based integration scripts and APIs. HB.js scripts work with all types of CICS applications without relying on screen scraping. HB.js is a complete solution for rapidly developing and deploying reusable Web services and/or scripts. That takes things a whole step further in integrating mainframe CICS applications with the outside world in general, not just staff working from home using a browser.

Some people may want to connect to the mainframe to develop code. One way to do that is to use Visual Studio Code, a source-code editor from Microsoft that runs on Windows or Linux. Users can then interact with z/OS in the Terminal window by using commands provided by IBM RSE API plug-in for Zowe CLI (RSE CLI plug-in), Zowe CLI, or both. The Zowe Explorer extension for VSCode lets users interact with data sets, USS files, and jobs that are stored on z/OS. The extension can be installed directly to VSCode to enable the extension within the GUI.

The real gold standard, the piece of software that seems to be missing from these choices that are available is web browser gateway software actually running on z/OS. It would allow z/OS applications to interoperate with other platforms (like Windows, Linux, and the cloud) in real time and users could interact with their mainframe in the same way that they do other platforms. There would be standard interfaces such as XML, HTTPS, and REST APIs. Interfaces that plenty of people are familiar with and could use easily, and there would be no need for specialists from other platforms.

And because this gateway software would actually run on the mainframe, there would be no need to access mainframe applications through a Linux of Windows server first. There would also be no need for any new hardware, or support, or repackaging. As far as the mainframe team would be concerned, they would simply install a piece of software on their mainframe – it could either run inside a z/OS based server address space or in a standalone address space – and everyone who was authorized could directly access any application functions they were authorized to access.

I guess everyone has their own favourite way of connecting remotely to a mainframe. ‘Green screens’ allow mainframe experts to work quickly and efficiently, and so terminal emulation is very common – and has been for a long time. I guess the important thing is to be able to get the work done remotely. However, there must be a better, more modern way of doing things, don’t you think?

Sunday, 6 June 2021

The Mainframe Mindset and the pandemic

Mainframers are generally fairly robust people who can spend hours happily problem-solving and getting on with their work. And, much like so many other people, mainframers have been working from home for much of the past 14 months. They have done their best with PC-based 3270 emulation software. They may have used VPN to ensure that their remote connectivity was secure. They may have tried connecting to CICS using a web browser. And they may have used the opportunity to try Zowe CLI and Zowe Explore. But – and this is a big but – they will have faced the same problems that other people have spending time away from the office.

The thing about working at the office is that everything is there (somewhere). When mainframers are faced with a technical issue, they can find cables etc, they can access high-speed business-class networks, and they can see dashboards showing the state of play of everything. Working from home isn’t like that. On the plus side, obviously, there’s no commute, no problems parking, etc. It’s possible to get up in the morning and sit down by a laptop in your pyjamas eating your breakfast and answer emails. And that sounds perfect. The problem is that not everything you need to do your job is at your fingertips. In addition, your home is your home, and quite often doesn’t also convert well to an office environment. And that can make life more stressful than it would be in the office.

Now stress actually comes in three types. There’s the stress that you can cope with. That’s really your level of resilience. It explains why some people can face very difficult situations and just seem to cope, while other people seem to really struggle with the same situation. The second type of stress is the stuff that makes you stronger. It’s like putting your body under stress at the gym or by going out for a long run. It’s sometimes called eustress, and, as I said, it makes you stronger. The third type of stress is stress that has an adverse effect on you – usually resulting in a fight or flight response. This also comes in two types. There’s ad hoc stress, which is basically where you think you see something frightening for a couple of minutes. And there’s chronic stress, where the stress continues over long periods of time and your body is constantly bathed in cortisol from the adrenal gland. And the longer that goes on, the more likely someone is to become irritable, anxious, or depressed.

That idea ties up nicely with what medical teams have reported over the past year, there seems to have become a growth in the number of people who are reporting symptoms of depression, anxiety, and irritability.

It’s a fact known to neuroscience that people tend to do what they have always done, ie they are more likely to get into habits and go through actions without thinking. They always put on the same sock or same shoe first. They always walk in through the front door and throw their keys on the nearby shelf. And then they always boil a kettle or always pour themselves a drink. Typically, the brain uses about a fifth of all the energy that the body has and about a fifth of all the oxygen that is transported round in the blood. And it uses more energy and oxygen when it thinks about something. So, it tries to do as much as possible without thinking – ie by habit. Now, it’s quite possible for executive function – the thinking part of the prefrontal cortex – to overrule a habit. And, it can decide on a new behaviour. But unless it’s very definite about the decision, it seems that the old habits will creep back. So, if you like to have a late-night snack or drink, then you are more likely to get into the habit of not only doing it every night, but also starting earlier. And this could explain why a number of people are eating and drinking more while spending so much time at home.

There is another reason. Eating gives your brain a small reward. You get a tiny opioid hit, which is a nice feeling. If you are feeling a bit low, then it’s nice to get a nice feeling in your brain. And so, you just keep eating – binge eating – to get that reward. And after a few months of lockdown, you find that you are putting on quite a bit of weight.

Many mainframers and others have been feeling lonely working from home and not seeing colleagues. Somehow, a Teams or Zoom meetings isn’t quite the same as actually having a chat with colleagues. Often lonely people aren’t living on their own, they are, perhaps, living with the ‘wrong’ people – people who don’t understand their work and the things that are important to them. Isolation or loneliness has been a big issue during the pandemic.

One of the issues with working from home is that people tend to get up and change rooms and start work. They stop work, maybe watch TV, and then go back to bed. They don’t get very much exercise and, consequently, they don’t sleep very well. And that leaves them tired and less able to perform well the next day. Sometimes, they take a much-needed nap in the afternoon. That then impacts on their ability to sleep the next night. You can see how the vicious cycle goes on. Many homeworkers have found themselves getting poor sleep. The answer is to go for, at least, a 30-minute brisk walk every day (whatever the weather). It’s also a good idea to keep to the same bedtime and get-up times. And stop using screens about an hour before bed.

Many people have reported strange dreams, not just nightmares, but unusually weird dreams. In the general run of things, people don’t remember their dreams, certainly not once they have got out of bed. Of course, every now and again people do remember a dream. It seems that, during lockdown, more people have been reporting more bizarre dreams!

The other problem that many mainframers and others have faced during the pandemic is worry about what might happen. What might happen to them or their family and friends if they become ill or very ill; what might happen to the local infrastructure if lots of people become ill, ie will there still be fresh water coming through the pipes, what if there are power cuts, etc? This can lead to people spending long periods of time brooding. Erma Bombeck said that worry (like brooding) “is like a rocking chair: it gives you something to do but never gets you anywhere”. Brooding can use up a lot of time and energy, but doesn’t achieve anything. The other problem with it is that the brain can’t tell the difference between real events and imagined events. So, all the doom and gloom that brooding creates makes the brain think that these events are going on in the outside world and it needs to protect itself from them. The consequence is that it can be hard to break out of the cycle of brooding and actually get back to real life.

Many people have found themselves home all day with their family, which, over time, in some cases, has led to them experiencing relationship issues with their partner and other family members. They are just not used to spending so much time together.

And many people have found themselves feeling quite depressed about everything – their life, their relationships, their job, their chances of becoming seriously ill, everything. One theory about depression is that it results in a reduction in neuroplasticity – that’s the brain’s ability to restructure itself, ie move neurons around as needed. In effect, it becomes hard to learn anything new. And that’s what makes it so hard for mainframers and everyone else to get out of a period of depression. What’s needed is a way to boost neuroplasticity, which is what some drugs do. Sadly, depression is the most common mental health problem worldwide.

As people find themselves getting more stressed, they also find their phobias getting worse. And many people have a phobia of needles – which makes it harder for them to be vaccinated against Covid-19. Some people faint when they see a needle, some associate needles with previous unpleasant events, some don’t like needles or being restrained, and some people feel much more pain than most others. And some people have combinations of these responses. So, some mainframers are avoiding getting the vaccine, which may be causing them more stress.

And there are some mainframers and others who, having been anxious during the crisis, are now anxious about going back to the office, back into the city to start work, back meeting and being with people.

Just to recap, your mainframers’ mindset has had to deal with stress, anxiety, depression, anger issues/irritability, feeling fed up, brooding, relationship issues, loneliness, isolation, insomnia, strange dreams, binge eating or drinking, weight issues, and needle phobia and other phobias. People have done very well to overcome all of those. And the good news is that we think we’re pretty much through the worst of it now!