That is *exactly* how IBM handles it for z/OS. I am one of two people at my location with access to the ResourceLink security portal. You ever wonder why you go looking for the APAR info for a PTF, and you get a "document not found" type of error? When we are actively applying maintenance, I pull down the SECINT SMPE ++ASSIGN data, so that I can select and apply PTF's that have security vulnerability implications.
_____________________________________________________________________________________________________ Dave Jousma AVP | Manager, Systems Engineering Fifth Third Bank | 1830 East Paris Ave, SE | MD RSCB2H | Grand Rapids, MI 49546 616.653.8429 | fax: 616.653.2717 -----Original Message----- From: IBM Mainframe Discussion List <[email protected]> On Behalf Of Nightwatch RenBand Sent: Tuesday, May 7, 2019 10:50 AM To: [email protected] Subject: mainframe hacking "success stories"? **CAUTION EXTERNAL EMAIL** **DO NOT open attachments or click on links from unknown senders or unexpected emails** Publishing "success stories" is a two edged sword. Don't and other installations cannot protect against the attach. Do and you spread the idea among the bad guys. It would seem that the best solution is: 1) Only discuss with people who have clearances and a "need to know", 2) Come up with a fix immediately 3) Put the fix in required maintenance and require that installations stay current. Never mention what is in the fix. Of course this great power to the vendor comes with great responsibility. (thanks, Stan Lee) ---------------------------------------------------------------------- For IBM-MAIN subscribe / signoff / archive access instructions, send email to [email protected] with the message: INFO IBM-MAIN **CAUTION EXTERNAL EMAIL** **DO NOT open attachments or click on links from unknown senders or unexpected emails** This e-mail transmission contains information that is confidential and may be privileged. It is intended only for the addressee(s) named above. If you receive this e-mail in error, please do not read, copy or disseminate it in any manner. If you are not the intended recipient, any disclosure, copying, distribution or use of the contents of this information is prohibited. Please reply to the message immediately by informing the sender that the message was misdirected. After replying, please erase it from your computer system. Your assistance in correcting this error is appreciated. ---------------------------------------------------------------------- For IBM-MAIN subscribe / signoff / archive access instructions, send email to [email protected] with the message: INFO IBM-MAIN
