Showing posts with label RACF. Show all posts
Showing posts with label RACF. Show all posts

Sunday, 13 November 2011

Guest blog – Mainframe security: who needs it?

This week, for a change, I’m publishing a blog entry from Peter Goldberg, a senior solution architect at Liaison Technologies, a global provider of cloud-based integration and data management services and solutions based in Atlanta. He works directly with customers to identify their unique data security and integration challenges and helps to design solutions to suit their organizations’ requirements. A frequent speaker at industry conferences on eBusiness security issues and solutions, he can be reached at pgoldberg@liaison.com.

I’ve been helping companies on both sides of the pond solve their data security problems for many years now. If I’ve learned one thing, it’s this: when I go into an organization that runs Windows, there’s little question of the need for data security. The organization knows it and so do I. When I visit a company whose IT infrastructure revolves around a mainframe, however, the mindset is often quite the opposite. In fact, the biggest data security misconception I encounter is the belief that the mainframe environment is inherently secure. Most IT staff view the mainframe as just another network node. Why? Because it’s universally perceived as a closed environment and, therefore, invulnerable to hackers.

In some cases, it’s the mainframe IT pros who hold this conviction. In other instances, it’s the executive management team. Lack of management attention allows “bad practices” to continue. I can tell you this without reserve: data stored in mainframes needs protection just as much as sensitive information stored on a Windows server or anywhere else. And, as systems continue to support more data, users, applications, and services, effective security management in the mainframe environment becomes significantly more difficult.

News flash: mainframes can be hacked!

For that simple reason, mainframe security should not be taken for granted.

Even though the mainframe is a mature platform, there is a real shortage of mainframe-specific security skills in the market. And, the few mainframe security practitioners who are out there spend a lot of time implementing configuration and controls within their environments as well as putting into place security systems like RACF, which provide access control and auditing functionality. As for other security measures, in my experience, the mainframe people know about encryption, but they’re not terribly aware of newer data security techniques like tokenization as it relates to protecting data within the mainframe environment and beyond.

Tokenization is a data security model that substitutes surrogate values for sensitive information in business systems. A rapidly rising method for reducing corporate risk and supporting compliance with data security standards and data privacy laws, it can be used to protect cardholder information as well as Personally Identifiable Information (PII) and Protected Health Information (PHI).

In fact, for companies that need to comply with the Payment Card Industry’s Data Security Standard (PCI DSS), tokenization has been lauded for its ability to reduce the cost of compliance by taking entire systems out of scope for PCI assessments. And, even in companies that do not deal with PCI DSS or other mandates, tokenization has proven effective for managing the duplication of data across LPARs and for facilitating the usage of potentially sensitive data for development purposes.

Too often, compliance audits skim over mainframe control weaknesses and there are also fewer mainframe-specific security guidelines. But this does not mean that significant risk is not there. You can apply a risk-based, defence-in-depth approach within the mainframe environment by using stronger mainframe host security controls and by using tokenization to protect the data itself.

To beef up data security on a mainframe, here’s my advice:
  1. Bring in mainframe security experts to identify and remediate risks, and to develop and enforce security policies and procedures.
  2. Develop in-house capabilities and skilled professionals across the mainframe platform to support security initiatives.
  3. Evaluate available security configuration and administration tools – there are some really good ones out there.
  4. Apply an in-depth security strategy that includes secure access and authentication controls, and use them appropriately.
  5. Adopt encryption and tokenization to protect sensitive information. Through their proper implementation, it’s really not that hard to achieve a true high level of protection within the mainframe environment.

Protecting sensitive and/or business-critical data is essential to a company’s reputation, profitability, and business objectives. In today’s global market, where business and personal information know no boundaries, traditional point solutions that protect certain devices or applications against specific risks are insufficient to provide cross-enterprise data security. Combining encryption and tokenization, along with centralized key management, as part of a corporate data protection programme works well – including in mainframe-centric environments – for protecting information while reducing corporate risk and the cost of compliance with data security mandates and data privacy laws.

Don’t be fooled: your mainframe isn’t inherently secure. Doing nothing is no longer an option!

Thanks Peter for your guest blog.
And remember, there's still time to complete the mainframe user survey or place a vendor entry in the Arcati Mainframe Yearbook 2012.

Sunday, 24 October 2010

Mainframe security

RACF (Resource Access Control Facility) from IBM has been around for so long that I guess we take it for granted. It is one of the “big three” External Security Manager (ESM) products for mainframes. The other two are ACF2 (Access Control Facility 2) and Top Secret, both of which are owned by CA. But, as they like to say on impartial radio and TV programmes, other security products are available!

For example, Alexandria, Virginia-based Type80 (www.type80.com) provides SMA_RT, which functions as a security monitor program product that looks for patterns of abuse and sends real-time alerts. It supports systems environments across multiple CPUs and over geographically diverse locations.

Las Vegas, Nevada-based Vanguard Integrity Professionals (www.go2vanguard.com) provides solutions for identity and access management, audit and compliance, security administration, and intrusion detection. For security management there’s Vanguard Administrator, Vanguard Advisor, and Vanguard SecurityCenter. For audit and compliance they provide Vanguard Analyzer, Vanguard incompliance, Vanguard Enforcer, and Vanguard Policy Manager. For access management there’s Vanguard Authenticator, Vanguard ez/SignOn, Vanguard ez/Token, Vanguard Tokenless Authentication, Vanguard ez/Integrator, and Vanguard PasswordReset. And for intrusion detection there’s Vanguard Enforcer (again).

Naples, Florida-based Advanced Software Products Group (ASPG) (www.aspg.com) provides a number of data security products including: MegaCryption, its file level encryption tool; ReACT, which automates the password reset and synchronization process; ERQ (Easy RACF Query), its automated ISPF RACF administrative and reporting utility; CryptoMon its ICSF analyser; and Secure/FTP, which provides a full audit trail of all FTP commands that were executed or attempted and offers online monitoring of all active FTP sessions.

While mentioning encryption, IBM has its Integrated Cryptographic Service Facility (ICSF) and a Cryptographic Coprocessor. And, of course, in terms of security, there’s also IBM’s Tivoli zSecure Suite.

Hackensack, NJ-based Bsafe Solutions (www.bsafesolutions.com) offers: Bsafe/Enterprise Security for MVS TCP/IP for network security; Bsafe/Security for CICS-MVS, providing extended security for DB2, IMS, and VSAM; and Bsafe/Enterprise Security for CICS, providing control of mainframe security from a PC.

Torrance, CA-based Data21 (www.data21.com) has ZIP/390, which enables zSeries batch jobs to send and receive PGP (Pretty Good Privacy) files.

Aliso Viejo, CA-based Quest Software (www.quest.com) has a number of security products that came with its acquisition of PassGo Technologies. Its mainframe security tools include: GoPlex, a full screen interface allowing users to control and view users logged on to any of the PassGo’s MultSess, NC-Access, or NCI/XF products; NC-Pass Network Security Managers, which protect information by directing the user to permitted applications only using their user ID and password; Defender ME uses tokens that provide security – there’s Defender ME VSSE for VTAM Session Security, Defender ME Secure for active network security, and Defender ME Authenticator for almost everything; NC-Syncom provides password synchronization spanning multiple systems, servers, networks, and applications; and NC-Access, a session manager. In addition, for VTAM networks, Quest provides: MultSess, a session manager; and NCI/XF, a programming tool for tailoring, customizing, and extending functionality for 3270 terminals and developing single point of entry VTAM network systems.

There’s definitely other mainframe software products out there, and it’s interesting to see just what is available.