Home Contact Pirean Press Resources Site Map  

Consul

Mainframe plug-ins: zLock

Policy enforcement.

In many organizations, administrators and regular users can issue RACF commands that do not comply with installation security policies or other corporate standards. Breaches occurring due to this lack of compliance can cause outages and enhance vulnerabilities. Consul InSight zLock provides an additional layer of security that enables organisations to clear RACF commands versus policies, before processing, thereby enforcing security standards on top of the RACF rules. zLock is integrated with RACF, and its rules are managed with RACF profiles.

zLock's features include:

Comprehensive policy enforcement:

Taking you beyond standard RACF:

Each time any RACF command is issued, Consul InSight zLock is invoked to verify all command keywords against your specified policies. Policies may be specified by the system administrator via RACF profiles. These profiles provide information to Consul InSight zLock about the type of verification to be performed, and about the action to be taken if the command does not comply with your policy. If desired, zLock can generate immediate, real-time alerts if critical RACF commands are issued. It can also prevent system outages which can be caused by system administrators issuing incorrect RACF commands with unintended consequences. zLock intercepts every RACF command before it is executed and verifies them against your company policies and procedures. When a command is entered by any means, zLock verifies if it complies with security policies and blocks it if it doesn’t.

Business Benefit:

  • Prevent non-compliant RACF commands, reduce database pollution
  • Reduce need and time for RACF clean-up and audits
  • Increase security control, even while decentralizing the administration
  • Prevent non-compliant PERMIT commands
  • Decentralize segment management
  • Enforce naming conventions
  • Reduce the risk of security breaches
  • Enhance RACF functionality
  • Avoid or replace expensive home grown programs or routines
  • Work proactively, instead of reactively
  • Enforce policy directly via RACF profiles