Audience
RACF Security Administrators, RACF Auditors and CICS System Programmers would benefit from this course.
Prerequisites
Anyone needing a good understanding of CICS and RACF Security
Duration
3 days.
Course Objectives
This 3 day course provides an understanding of how CICS and RACF communicate when it comes to security. The course covers a basic introduction to CICS and RACF.
The attendee will be able to describe the RACF Classes that secure CICS resources. In addition, the attendee will learn how the CICS security parameters are used to enable
RACF security and which parameters affect each CICS resource. CICS Intersystem Communication security levels are covered as is CICS Web Services. There is an
introduction to CICS/DB2 security. Attendees will have completed a number of workshops on a CICS/TS 6.x system.
Course Content
Day 1
CICS Overview
- Resources that can be defined
- Resources that can be secured
- Commands that can be secured
- Workshop Defining and running CICS Transactions
RACF Overview
- Defining Groups
- Defining Users
- RACF Classes that control CICS Resources and Commands
- Universal Access and Access lists
- RACLIST
- General Resources
Workshop Listing and Analyzing RACF Security options
Day 2
Protecting the CICS Region
CICS Sign-on security
Creating the RACF Accessor Environment Element
CICS Parameters that enable RACF security
Defining Classes in the Class Descriptor Table
Transaction Security
- TCICSTRN
- GCICSTRN
Workshop Enabling RACF Security
Resource Level Security
SPI Command Level Security
Workshop Defining Transaction Security
Workshop Defining Resource Level Security
Day 3
CICS Intersystem Communication Security
- Bind and Link security
- Attachsec Security
RACF Started Procedures Table
- Defining CICS Started Tasks
Introduction to CICS/DB2 Security
- DSNR Access
Overview of CICS Security with Web Services
- CICS support for Secure Sockets Layer
- CICS support for Transport Layer Security