Previous Topic: How to Define SAF Authorization LevelsNext Topic: Securing Actions Using the FUNCEQUE Entry


Map Authorization Values

CA ACF2 for z/OS, and CA Top Secret for z/OS users should be aware that a secondary mapping of the RACROUTE authorization value to CA Top Secret for z/OS or CA ACF2 for z/OS equivalents occurs in the SAF interface supplied with CA ACF2 for z/OS or CA Top Secret for z/OS.

The following are the map authorization values:

SAF Value

RACF Values

CA ACF2 for z/OS Value

CA Top Secret for z/OS Value

Read

Read

Read

Read

Update

Update

Write

Update

Control

Control

Write

Control

Alter

Alter

Allocate

Control

Note: If you specify a value other than READ you may need to update the SAF authorization when a new release of your site security package alters mapping values.

The required access level is determined at the action initiation security control point. You should be aware that CA ACF2 for z/OS, and CA Top Secret for z/OS downgrade the control authority to UPDATE or WRITE for non-VSAM data sets. You must take this into account when setting up ESI security rules.