S 2.295 System administration of z/OS systems

Initiation responsibility: IT Security Officer, Head of IT

Implementation responsibility: Administrator

The system administration of z/OS systems is divided into different areas. For many tasks, there are experts in the computer centres who often only perform very specific activities on the z/OS systems. The following recommendations relating to system administration should be considered:

Division into roles

A role concept should be implemented. This allows assigning of system authorisations to the roles and therefore facilitates the work of the RACF administrators.

In order to reduce the assignment of high authorisation attributes in the RACF, it should be considered to divide the administration at least into the following roles:

Substitute arrangements

Substitute arrangements must be in force for all important system administration roles. An important role must never be staffed with only one person. More detailed information regarding this can be found in S 3.10 Selection of a trustworthy administrator and his substitute.

Review questions: