About the only concept of a 'field' in dataset/files is a descriptor word (block/record length) and VSAM keys.
What you call a 'field' is not meaningful to anything but *very* specialized software. You would have to thread *all* possible accesses through that software. And there are a *lot* of ways to access data. Not easy even for DBMS software and your security package. But that's about the only way. -----Original Message----- From: IBM Mainframe Discussion List [mailto:[EMAIL PROTECTED] On Behalf Of Gil, Victor x28091 Sent: Thursday, March 23, 2006 2:14 PM To: [email protected] Subject: How to "marry" subsystem and dynamic allocation Good afternoon, IBM-MAIN We'd like to be able to prevent certain "confidential" fields in production files from being revealed to "unauthorized" users while still allowing access to the rest of the record. From the users prospective these files are read-only and are accessed through TSO, batch or CICS for testing or comparison purposes. ---------------------------------------------------------------------- For IBM-MAIN subscribe / signoff / archive access instructions, send email to [EMAIL PROTECTED] with the message: GET IBM-MAIN INFO Search the archives at http://bama.ua.edu/archives/ibm-main.html

