RULE mode lets you migrate to full ABORT mode on a rule set basis. There are three action values that you can set for RULE mode (one for access rules, one for command limiting rules, and one for diagnose limiting rules). One value tells CA ACF2 for z/VM what to do if no rule exists on the Rule database. If a rule exists, CA ACF2 for z/VM checks the setting in the $MODE control statement for a mode for that rule set. You can also instruct CA ACF2 for z/VM in what to do if no $MODE control statement exists. For each of the three action values, you can specify QUIET, LOG, WARN, or ABORT. RULE mode gives you maximum flexibility when implementing security. It allows you to target your critical object for abort protection, while leaving less critical objects in QUIET, LOG, or WARN mode.
|
Copyright © 2009 CA Technologies.
All rights reserved.
|
|