Previous Topic: Identify and Secure DB2 Data SetsNext Topic: Test PERMITs Using TSSSIM (optional)


Protect Distributed Data Facility (DDF) Resources

DB2 enables client applications that run in a remote environment to access data in a local DB2 server. It also enables local DB2 applications to access data at remote relational database systems.

You should associate the address space of the subsystem with a DB2 facility using MASTFAC. Each user will need to be granted access to this facility along with the appropriate DSNR.subsys.DIST connection resources.

The security package (for example, CA Top Secret, CA ACF2, RACF) that manages the subsystem on which the DB2 objects reside, determines what security restrictions will apply. For example, if subsystem A is the local subsystem and if the DB2 objects are maintained on subsystem B, access authorizations are determined by the security package in effect for system B.