Re: [EXTERNAL] Re: The Local death of DB2 z/OS --- what is the best way to preserve the data once the mainframe is gone

2023-02-09 Thread Bob Bridges
I have had management sign off on the risk after I estimated the effort it 
would take to remediate an issue.  Being a security geek myself, sometimes I 
disagree with the risk; other times I think they're being reasonable.  But I'm 
not the one entrusted with that decision, after all.

But yeah, gotta admit that some management teams feel they have to fix 
everything the auditors point at.

---
Bob Bridges, robhbrid...@gmail.com, cell 336 382-7313

/* Humour is the only test of gravity, and gravity of humour, for a subject 
which will not bear raillery is suspicious, and a jest which will not bear 
serious examination is false wit.  -Aristotle */

-Original Message-
From: IBM Mainframe Discussion List  On Behalf Of 
Pommier, Rex
Sent: Thursday, February 9, 2023 16:17

OK, most auditors don't shoot the survivors directly, but in many instances, 
the company's management simply takes the auditors at their words and shoot the 
survivors on behalf of the same auditors.  In my career, I've been in both 
positions; that of having blind management and having management who asked my 
position before making decisions.  

-Original Message-
From: IBM Mainframe Discussion List  On Behalf Of Bob 
Bridges
Sent: Thursday, February 9, 2023 3:03 PM

Steve Thompson's reply about lawyers got to me to look at this bit about 
auditors.  Do auditors ~ever~ shoot the survivors?  In my experience, both 
internal and external auditors report to management; it is management who 
decide whether to fix the problem or sign off on the risk.

I don't think I'm prejudiced in this.  My degree is in Accounting, but I have 
never worked in anything but computer jockery of various kinds.  Well, wait, on 
two occasions I worked a one-week IT audit, supplementing the audit team as a 
mainframe SME.  (Auditors generally understand networks, but are helpless on 
mainframes.)  But that's all.

Those two occasions do match what you say about running years-old procedures, 
though.  Although from what I can remember, the checklist on RACF security that 
they gave me to follow was fairly complete.

---
Bob Bridges, robhbrid...@gmail.com, cell 336 382-7313

/* 'I Love Lucy' left here years ago and has gone past a few thousand stars.  
Only the nearby stars have seen 'The Simpsons.'  The earth is brighter than the 
sun at television frequencies.  -SETI astronomer Dan Werthimer */

--- On 2/9/2023 9:25 AM, Tom Longfellow wrote:
> my opinion of Auditors is pretty low.They just come in.   Rerun 
> procedures and checks developed in the 70's and published in a book.   With 
> no regard for the real world functions of the systems.And then they go to 
> the battlefield and "Shoot the survivors"

--
For IBM-MAIN subscribe / signoff / archive access instructions, send email to 
lists...@listserv.ua.edu with the message: INFO IBM-MAIN

--
The information contained in this message is confidential, protected from 
disclosure and may be legally privileged. If the reader of this message is not 
the intended recipient or an employee or agent responsible for delivering this 
message to the intended recipient, you are hereby notified that any disclosure, 
distribution, copying, or any action taken or action omitted in reliance on it, 
is strictly prohibited and may be unlawful. If you have received this 
communication in error, please notify us immediately by replying to this 
message and destroy the material in its entirety, whether in electronic or hard 
copy format. Thank you.


--
For IBM-MAIN subscribe / signoff / archive access instructions, send email to 
lists...@listserv.ua.edu with the message: INFO IBM-MAIN

--
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to lists...@listserv.ua.edu with the message: INFO IBM-MAIN


Re: [EXTERNAL] Re: The Local death of DB2 z/OS --- what is the best way to preserve the data once the mainframe is gone

2023-02-09 Thread a.benveni...@free.fr
We have such requirements related to the necessary need to restore data for 
clients who have legal controls, old active archives for decades…, and keep 
tapes in vaults in case of.
Next week we receive a client who needs to restore tapes created 10 years ago, 
never read since on I platform, we still maintain clients who run on z9 for 
example.
Clients accept a potential risk to not be able to repair materials, unreadable 
tapes… We stock old materials, pieces, network hardware to respond of such 
need/contract.

Alain Benvéniste
alain.benveni...@kyndryl.com
Resiliency Services for System Z platform
35 allée du clos des charmes
77090 Collégien
France


De : IBM Mainframe Discussion List  de la part de 
Paul Gorlinsky 
Date : jeudi, 9 février 2023 à 22:24
À : IBM-MAIN@LISTSERV.UA.EDU 
Objet : Re: [EXTERNAL] Re: The Local death of DB2 z/OS --- what is the best way 
to preserve the data once the mainframe is gone
Wouldn't you agree that ultimately, the CIO or CTO or highest Information 
Technology is responsible for any and all mishaps, including mistakes made by 
auditors? Hiring the correct auditor and giving them the correct scope of work 
which is the hiring companies responsibility.

I also saw this in state government, everything done by committee so that no 
one person would be the scape goat...

--
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to lists...@listserv.ua.edu with the message: INFO IBM-MAIN

--
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to lists...@listserv.ua.edu with the message: INFO IBM-MAIN


Re: [EXTERNAL] Re: The Local death of DB2 z/OS --- what is the best way to preserve the data once the mainframe is gone

2023-02-09 Thread Paul Gorlinsky
Wouldn't you agree that ultimately, the CIO or CTO or highest Information 
Technology is responsible for any and all mishaps, including mistakes made by 
auditors? Hiring the correct auditor and giving them the correct scope of work 
which is the hiring companies responsibility. 

I also saw this in state government, everything done by committee so that no 
one person would be the scape goat...

--
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to lists...@listserv.ua.edu with the message: INFO IBM-MAIN


Re: [EXTERNAL] Re: The Local death of DB2 z/OS --- what is the best way to preserve the data once the mainframe is gone

2023-02-09 Thread Pommier, Rex
Bob,

OK, most auditors don't shoot the survivors directly, but in many instances, 
the company's management simply takes the auditors at their words and shoot the 
survivors on behalf of the same auditors.  In my career, I've been in both 
positions; that of having blind management and having management who asked my 
position before making decisions.  

rex

-Original Message-
From: IBM Mainframe Discussion List  On Behalf Of Bob 
Bridges
Sent: Thursday, February 9, 2023 3:03 PM
To: IBM-MAIN@LISTSERV.UA.EDU
Subject: [EXTERNAL] Re: The Local death of DB2 z/OS --- what is the best way to 
preserve the data once the mainframe is gone

Steve Thompson's reply about lawyers got to me to look at this bit about 
auditors.  Do auditors ~ever~ shoot the survivors?  In my experience, both 
internal and external auditors report to management; it is management who 
decide whether to fix the problem or sign off on the risk.

I don't think I'm prejudiced in this.  My degree is in Accounting, but I have 
never worked in anything but computer jockery of various kinds.  Well, wait, on 
two occasions I worked a one-week IT audit, supplementing the audit team as a 
mainframe SME.  (Auditors generally understand networks, but are helpless on 
mainframes.)  But that's all.

Those two occasions do match what you say about running years-old procedures, 
though.  Although from what I can remember, the checklist on RACF security that 
they gave me to follow was fairly complete.

---
Bob Bridges, robhbrid...@gmail.com, cell 336 382-7313

/* 'I Love Lucy' left here years ago and has gone past a few thousand stars.  
Only the nearby stars have seen 'The Simpsons.'  The earth is brighter than the 
sun at television frequencies.  -SETI astronomer Dan Werthimer */

--- On 2/9/2023 9:25 AM, Tom Longfellow wrote:
> my opinion of Auditors is pretty low.They just come in.   Rerun 
> procedures and checks developed in the 70's and published in a book.   With 
> no regard for the real world functions of the systems.And then they go to 
> the battlefield and "Shoot the survivors"

--
For IBM-MAIN subscribe / signoff / archive access instructions, send email to 
lists...@listserv.ua.edu with the message: INFO IBM-MAIN

--
The information contained in this message is confidential, protected from 
disclosure and may be legally privileged. If the reader of this message is not 
the intended recipient or an employee or agent responsible for delivering this 
message to the intended recipient, you are hereby notified that any disclosure, 
distribution, copying, or any action taken or action omitted in reliance on it, 
is strictly prohibited and may be unlawful. If you have received this 
communication in error, please notify us immediately by replying to this 
message and destroy the material in its entirety, whether in electronic or hard 
copy format. Thank you.


--
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to lists...@listserv.ua.edu with the message: INFO IBM-MAIN