On April 17, 2026 a new service stream enhancement (SSE) to zSecure 3.2 has become generally available, providing support for digital certificates in the web user interface, support for the latest Center for Internet Security (CIS) IBM z/OS with RACF Benchmark, currency updates for RACF, ACF2, and Db2, and other enhancements. On March 27, 2026 support was added for the CIS IBM CICS for z/OS Benchmark standard as part of the quarterly compliance updates.
Background
IBM Z continues to be the home for mission critical information and essential business production applications in many organizations due to the strong heritage of integrated security support capabilities across hardware, operating system, software and applications. Resource Access Control Facility (RACF) is the foundational IBM package provided for protecting Z. The IBM zSecure portfolio builds on the security support in IBM Z, z/OS and RACF to enhance Z security capabilities.
IBM zSecure Admin boosts productivity for RACF administrators. While it usually generates RACF commands to make updates, the CKGRACF component can also directly update the RACF database; for example to set a password back to a user-defined default password in case of a lost password. The Access Monitor component can see security events that are not being logged and summarize all access requests. The RACF Offline component allows making updates to a RACF database that is not active, so as to be able to analyze the effective security changes after reorganizing security rules before activating them using the Access Monitor data. A plug-in to IBM z/OS Management Facility (z/OSMF) provides a web interface.
IBM zSecure Compliance helps review the security of the system in various ways, for example by formatting event log records from the System Management Facilities (SMF) and by running evaluations against compliance standards such as the Security Technical Implementation Guides (STIGs) from the United States Defense Information Systems Agency (DISA). zSecure Compliance also supports CA ACF2 and CA Top Secret, two alternatives to RACF. The zSecure Collect component collects system snapshot information. The product furthermore contains a compliance dashboard and an integrated set of micro-services that can run under IBM z/OS Container Extensions (zCX) or the OpenShift Container Platform on Linux on Z. z/OS compliance data is obtained from participating IBM components with the help of z/OSMF and the IBM Z Common Data Provider component. Some participating components delegate the actual data compilation to the z/OS Compliance Integration Manager component.
The common query language employed by zSecure Admin, zSecure Compliance, zSecure Manager for RACF z/VM, zSecure Alert, and zSecure Adapters for SIEM is called the CARLa Auditing and Reporting Language (CARLa).
Benefits
The updates recently shipped in the zSecure 3.2 service stream include the following enhancements:
- The Web UI component of zSecure Admin now provides many options to work with Digital Certificates (RA.5 menu).
- A new alert 1509 for certificate trust status changes
- A new standard Center for Internet Security (CIS) IBM CICS for z/OS Benchmark.
- Support for the CIS IBM z/OS with RACF Benchmark 1.0.0 standard from October 2025.
- Currency updates for RACF (OPTRACF and DSNRAUTH classes), and ACF2 (recent pass phrase related fields in the UI)
- Db2 updates (new IFCids, UI support for report types DB2_CONTEXT and DB2_ROLE, and more)
- Support for zERT monitoring updates provided with APAR PH63197
- Various user interface improvements as requested through submitted Ideas
For more details, see the refreshed zSecure 3.2 documentation There is a new "(April 2026)" section in What's new.
The latest compliance standard overview is here.
These enhancements primarily apply to zSecure Admin, zSecure Compliance, zSecure Alert, and zSecure Adapters for SIEM. Some also apply to zSecure Audit and IBM Z Security and Compliance Center.
Prerequisites
To fully benefit from these enhancements the following is required:
- IBM Security zSecure 3.2
- PTF UJ99423 for APAR OA69275 (this updates code shared among most zSecure components)
- PTF UJ99420 for APAR OA69276 (this updates code specific to the ACF2 features)
- PTF UJ99421 for APAR OA69282 (this updates code specific to zSecure Compliance and IBM Z Security and Compliance Center)
Migration
This April 2026 SSE comes with new menu options. If you use option SE.D.N to customize menus or options for your installation, then you must run SE.D.N again with a sufficiently authorized user ID.
For more details, you can look at the Release notes.
If you have any questions, please ask them here. The IBM zSecure today article serves as a starting point to reach all the latest zSecure announcements.