Tuesday, April 10, 2007

Security in DB2 for z/OS Versions 8 and 9

Hi DB2 User,

Here are several technical documents about Security in DB2 for z/OS Versions 8 and 9, available on IBM's website:

- Securing DB2 and Implementing MLS on z/OS (2007 Redbook Versions 8 and 9)
http://www.redbooks.ibm.com/Redbooks.nsf/RedbookAbstracts/sg246480.html?Open

- Protect, Retain and Comply with Your DB2 Data (Versions 8 and 9 in PDF and MP3)
by Roger Miller
http://www.ibm.com/support/docview.wss?uid=swg27007844

- New DB2 Improvements in Security (Versions 8 and 9)
by Roger Miller
http://www.ibm.com/support/docview.wss?uid=swg27007843


Version 8 only

- For Certain Eyes Only (Article from DB2mag)
by Sasirekha Cota
http://www.db2mag.com/story/showArticle.jhtml?articleID=17602318

- DB2 for z/OS V8 Security Topics, Including Multi-level Security (Version 8)
by Roger Miller
http://www.ibm.com/support/docview.wss?uid=swg27005803

- Best Practices in DB2 Security (Version 8)
by Roger Miller
http://www.ibm.com/support/docview.wss?uid=swg27007842


More Information about Security

- DB2 for z/OS & OS/390 Security: Protect Your Assets (Versions 6, 7 and 8)
by Roger Miller
http://www.ibm.com/support/docview.wss?&uid=swg27001877


IBM Technotes (FAQ) about Security

- Should I use the traditional DB2 security or RACF access control?

- Authority removed from external security definition (RACF), however user is still able to run the SQL statement. Dynamic statement caching is enabled

- Can encryption be turned on in the SYSIBM.USERNAMES table for the password column?

- SPUFI or DSNTEP2 message: NOT AUTHORIZED TO USE DB2 SUBSYSTEM xxxx

- Invalid Authorization ID with onlinecheck parameter when customizing an SQLJ program

- Running the RACF access control exit routine for DB2 Version 8 with the RACF database set up for DB2 Version 7

- Why do I get a RACF message even though the CREATE TABLE was successful?

- What is IBM's plan for internal and external security in DB2?

- Is that true that DB2 for z/OS, Version 8 is the last version that will support the internal security

- Does a DB2 user need the triggered action privilege in order to execute a trigger?

- Secondary authorization IDs from CICS to DB2

- Multilevel security: indexes on the security label column


Regards,

DB2usa.

Labels: , , , ,