That is *exactly* how IBM handles it for z/OS.  I am one of two people at my 
location with access to the ResourceLink security portal.   You ever wonder why 
you go looking for the APAR info for a PTF, and you get a "document not found" 
type of error?   When we are actively applying maintenance, I pull down the 
SECINT SMPE ++ASSIGN data, so that I can select and apply PTF's that have 
security vulnerability implications.

_____________________________________________________________________________________________________
Dave Jousma
AVP | Manager, Systems Engineering  

Fifth Third Bank  |  1830 East Paris Ave, SE  |  MD RSCB2H  |  Grand Rapids, MI 
49546
616.653.8429  |  fax: 616.653.2717


-----Original Message-----
From: IBM Mainframe Discussion List <[email protected]> On Behalf Of 
Nightwatch RenBand
Sent: Tuesday, May 7, 2019 10:50 AM
To: [email protected]
Subject: mainframe hacking "success stories"?

**CAUTION EXTERNAL EMAIL**

**DO NOT open attachments or click on links from unknown senders or unexpected 
emails**

Publishing "success stories" is a two edged sword.  Don't and other 
installations cannot protect against the attach. Do and you spread the idea 
among the bad guys.
It would seem that the best solution is:
1) Only discuss with people who have clearances and a "need to know",
2) Come up with a fix immediately
3) Put the fix in required maintenance and require that installations stay 
current.  Never mention what is in the fix.
Of course this great power to the vendor comes with great responsibility.
(thanks, Stan Lee)

----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions, send email to 
[email protected] with the message: INFO IBM-MAIN **CAUTION EXTERNAL 
EMAIL**

**DO NOT open attachments or click on links from unknown senders or unexpected 
emails**

This e-mail transmission contains information that is confidential and may be 
privileged.   It is intended only for the addressee(s) named above. If you 
receive this e-mail in error, please do not read, copy or disseminate it in any 
manner. If you are not the intended recipient, any disclosure, copying, 
distribution or use of the contents of this information is prohibited. Please 
reply to the message immediately by informing the sender that the message was 
misdirected. After replying, please erase it from your computer system. Your 
assistance in correcting this error is appreciated.


----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to [email protected] with the message: INFO IBM-MAIN

Reply via email to