This course teaches you how to implement security for your CICS systems using RACF as the external security manager. The lecture material will first explain the implementation tasks for a single-region CICS system and then extend the scope to MRO- or ISC-connected multiregion CICS systems. In the classroom you will learn both the CICS and RACF definitions necessary to establish effective security controls for CICS. You will learn how to: Protect CICS system resources so that CICS itself has access but other users, such as TSO users or batch jobs, are denied access. Define CICS terminal users to RACF and restrict the CICS regions to which these users will be allowed to sign on. Control access to individual CICS transactions. Control access to CICS application resources accessed by these transactions. Control execution of CICS system programmer interface (SPI) commands used within transactions. Control access to installation-defined resources used to support application-specific security requirements. Control access to CICS transactions and resources when two or more CICS address spaces are connected to enable use of the CICS transaction routing and function-shipping mechanisms. You will learn about the wide variety of mechanisms that can be used to initiate transactions within CICS and the techniques for imposing security controls on each of these mechanisms. These mechanisms include the connections to CICS using Advanced Program-to-Program Communication (APPC) either from CICS client or server products on other platforms or from other products that support APPC. You will also explore the security interface between CICS, RACF, and DB2 and learn how RACF can be used to secure CICSplex System Manager, one of the elements provided with CICS Transaction Server for z/OS.
You should be familiar either with: RACF (perhaps as a security administrator) or with CICS (perhaps as a member of your CICS technical support staff). It is not assumed or necessary that you already be familiar with both RACF and CICS.
This course is for security personnel and CICS support personnel responsible for designing, implementing, or administering RACF security for CICS Transaction Server systems.