It probably is but PCI DSS is a standard.  How does one electronically enforce 
it?  My security team can have everybody sign a statement saying they won't 
share their ID/password with their buddy at the next desk but that won't 
physically stop them.  

Rex

-----Original Message-----
From: IBM Mainframe Discussion List <[email protected]> On Behalf Of 
Charles Mills
Sent: Wednesday, February 16, 2022 4:34 PM
To: [email protected]
Subject: [EXTERNAL] Re: How to Get UserID in non-TSO REXX

Prohibited by PCI DSS, is it not?

Charles


-----Original Message-----
From: IBM Mainframe Discussion List [mailto:[email protected]] On Behalf 
Of Bob Bridges
Sent: Wednesday, February 16, 2022 2:32 PM
To: [email protected]
Subject: Re: How to Get UserID in non-TSO REXX

Two ~humans~ can use the same ID.  But RACF cannot prohibit that, for RACF can 
never know it.

For most purposes the security folks should prohibit it, if they're allowed to. 
 But I suppose there may be cases where it's not the worst thing in the 
world...very ~rare~ cases.

----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions, send email to 
[email protected] with the message: INFO IBM-MAIN

----------------------------------------------------------------------
The information contained in this message is confidential, protected from 
disclosure and may be legally privileged. If the reader of this message is not 
the intended recipient or an employee or agent responsible for delivering this 
message to the intended recipient, you are hereby notified that any disclosure, 
distribution, copying, or any action taken or action omitted in reliance on it, 
is strictly prohibited and may be unlawful. If you have received this 
communication in error, please notify us immediately by replying to this 
message and destroy the material in its entirety, whether in electronic or hard 
copy format. Thank you.


----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to [email protected] with the message: INFO IBM-MAIN

Reply via email to