Previous Topic: PERMIT Command for Defining Utilities Permission for RACF

Next Topic: Defining Security Protection Profiles in CA Top Secret

Sample Utility Protection Scenario Using IBM Security Server RACF

This sample utility protection profile prevents all users, by global default, from being able to execute the TBESHOW database list utility. However, user SYSTEMS can list the BES1 database.

RDEF CA@BES BES.UTILITIES.PROTECT
RDEF CA@BES BES1.UTILITY.TBESHOW                                    
     OWNER(SECADMIN)                                                
     DATA('CA Tape Encryption BATCH UTILITY PROTECTION'  )
PE   BES1.UTILITY.TBESHOW CLASS(CA@BES) ACCESS(READ)                
     GENERIC ID(SYSTEMS)