We are currently surveying how CA 7 customers are handling security for CA 7 PROD environments. Most organizations that we work with are leveraging ESMs (TopSecret, RACF, and ACF2) for CA 7 security in PROD; a few of them use CA 7 internal security in non-PROD environments. Have you transitioned to using external security managers to satisfy enterprise security and audit requirements? Is anyone here still using CA 7 internal security in PROD environements?