You may wish to create some group profiles for your users &/or
applications.
By grouping your users and applications in group profiles, you can turn
off & on authority in a hurry and secure your information.
Create a test group profile & regular profile, remove the regular
authorities, & test things out.
If you are in no big hurry on locking down things, you can prioritize
your data and take it a library or application at a time.
Systems are shipped now at Sec Level 40.
The next step, moving to 40 from 30 isn't too big of a step as long as
you don't have applications that abuse the O/S. Just change your audit
levels, monitor for potential failures, & make the jump.
I would advice checking out the info center and knowledge base as well.
Here is a snip from the info center .....
Passwords are required and users' access is based on their authority
(30)
All requirements of security level 20 are met.
The user must have the specific authority required to access all system
resources.
Only user profiles created with security officer (*SECOFR) security
class are given all object (*ALLOBJ) authority automatically.
Protect from undocumented system interfaces (40)
All requirements of security level 30 are met.
Programs fail if they try to access objects through interfaces that are
not supported.
If a job specifies a user profile, users must have the use authority
attribute to the profile in addition to the use authority attribute to
the job they want to use.
Thanks.
James Salter
Systems Programmer
American Cast Iron Pipe Company
phone (205) 325-3033
fax (205) 307-3833
from: Booth Martin <booth@xxxxxxxxxxxx>
subject: Moving from Security Level 20 to Security Level 30
We are considering moving from security level 20 to security level 30.
This is an old system, dating from sys/36 days, running on a v4r25 box.
So far I can't see any serious gotcha's, but my experience tells me that
asking the questions ahead of time is a useful idea.
Are there gotchas that you can think of that we need to be looking for?
As an Amazon Associate we earn from qualifying purchases.
This mailing list archive is Copyright 1997-2025 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact
[javascript protected email address].
Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.