John,

Just following up on your comment re your curiosity re IEFOPZxx debate on the 
GSE UK LSG Agenda.

We will debate IEFOPZ from two perspectives:

The first being how, why and when to use it, as its one of those topics that 
can potentially just slip by if the techies are not paying attention.

The second and the more interesting discussion will be around any potential 
security issues that could be exploited, by a rogue user, who has update or 
higher access to PARMLIB, couple with some patience or the ability to 
dynamically enable this for a given program.

Given they could introduce their own code into the system, there are several 
security questions to be asked:


·         what security controls are available to us?

·         What monitoring solutions are they if this is dynamically changed?

·         What controls should/must be deployed?

I have to write a few slides on this over the coming week and may come up with 
more questions than answers!

Hope this helps….

Mark

Mark Wilson | Technical Director | RSM Partners Ltd

Head Office:  +44 (0) 1527 837767
Mobile:          +44 (0) 7768 617006
Email:            ma...@rsmpartners.com<mailto:ma...@rsmpartners.com>
Web:              www.rsmpartners.com<http://www.rsmpartners.com/>

GSE Information
Large Systems Working Group Chairman
www.lsx.gse.org.uk

GSE UK Conference Manager
www.gse.org.uk/tyc
Email: mark.wil...@gse.org.uk<mailto:mark.wil...@gse.org.uk>



----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to lists...@listserv.ua.edu with the message: INFO IBM-MAIN

Reply via email to