Mainframe Cybersecurity & Compliance

  • 1.  Compare ACF2, TopSecret and RACF

    Posted Dec 10, 2008 01:42 AM
    Hi,  Can somebody please explain  1) The difference between ACF2, TopSecret and RACF.  2) The  merits and drawbacks of each of  them.    3) On what basis  a  Organization select one of these tools.  4) Why CA is having two  products (ACF2 and TopSecret).  Thanks in advance

    #TopSecret


  • 2.  Re: Compare ACF2, TopSecret and RACF

    Posted Jan 06, 2009 06:06 AM
    I don't have TopSecret or RACF experience, but I'll take a shot at this.  ACF2 and TopSecret are designed on the principle of 'security by default'.   In other words if there is no access rule to validate against, then access is prevented.   RACF is the opposite; basically you must write an access rule to deny access to a computing resource.    Which approach is 'better' will most likely be debated for some time to come.   The merits of each method depend on the type of environment you are administering.   Should development be supported at the cost of security?   Do developers require unfettered access to create, modify, and delete dataset names, and resources?   On the flip side, do you want to exercise greater control over your environment and prevent access to anything/everything that has not been subject to whatever methodology (e.g. change management) is used to ensure a stable computing environment?   I don't mean to imply that one security application is more secure than another, just that each requires a different approach when designing a security architecture.  Acquisitions of companies by CA in years gone by have added to the catalog of products that they support.   I cannot speak as to why they still sell both products and have not encouraged or even forced a migration one way or the other.   Bottom line, every company wants to grow market share.   In my opinion, whether they dominate the market by selling one product or many is irrelevant.    

    #TopSecret


  • 3.  Re: Compare ACF2, TopSecret and RACF

    Posted Jan 12, 2009 03:11 PM
    Follow-up:   I learned today that RACF has a setting that will modify the  default to no access.

    #TopSecret


  • 4.  Re: Compare ACF2, TopSecret and RACF

    Posted Jan 19, 2009 10:14 PM
    Hi Carlos_M,  Thanks a lot for sharing your knowledge with me.  It will be good if  somebody is able to provide more details on this.  RegardsJagadeesan

    #TopSecret


  • 5.  Re: Compare ACF2, TopSecret and RACF

    Posted Apr 29, 2009 01:41 AM
    RACF also has a faciltiy where all resources can be protected by default and the option is called PROTECT ALL.

    #TopSecret