Previous Topic: Special Purpose IMODs

Next Topic: User IDs

System Security

IMODs executing in a CA‑GSS address space can access and update a variety of data sets and data areas. To prevent unauthorized activity, CA‑GSS supports system security software that is compatible with the System Authorization Facility (SAF), including CA ACF2, CA Top Secret, and IBM RACF.

In z/OS, each task operates under the control of an access control environment element (ACEE), which controls access to all resources. SAF‑compatible security software maintains the ACEE based on a user ID and ensures that the necessary checks are provided. CA‑GSS ensures that an appropriate ACEE is in place for each executing IMOD and that all services invoked on behalf of the IMOD execute under the scope of that ACEE.