IBM Security for Z

Security for Z

Join this online user group to communicate across Z Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only

Introducing IBM zSecure Access: Modernizing access management on IBM Z

By Rashi Sharma posted 22 days ago

  

IBM is introducing IBM zSecure Access, a new solution that brings access administration, policy enforcement and access assessment together to modernize RACF administration. 

For decades, RACF has provided foundational protection for IBM Z. IBM zSecure Access builds on that trusted foundation to help organizations reduce access risk, simplify security operations, and make critical RACF capabilities accessible to broader security teams. 

As frontier AI increases the speed and sophistication of cyber threats, strong access governance becomes even more important. Organizations need to know not only who can access critical systems, but whether that access is appropriate, continuously governed, and protected from misuse. 

IBM zSecure Access helps put that principle into action. 

Strengthening access control for the age of AI-speed threats 

Managing access across users, applications, and system resources is increasingly complex. RACF administration often relies on deep expertise, manual coordination, and fragmented processes. Commands may be reviewed only after execution, while access granted for a former project, role or employee can remain long after it is needed. 

Risk can accumulate quietly until an audit or an outage brings it to light. Meanwhile, many organizations struggle to answer a foundational question: Who has access to what, and is that access still warranted? 

In an environment where threats can move faster, delayed visibility and unnecessary privilege create greater exposure. Security teams need a more proactive way to administer access, enforce policy and maintain a clean access environment—without disrupting the RACF and SAF architecture protecting their most critical systems. 

This is where IBM zSecure Access comes in. 

Bringing administration, governance and enforcement together 

IBM zSecure Access transforms RACF administration into a unified, policy-driven operational layer. Built natively within the RACF and SAF security architecture, it modernizes access management without external overlays, agents, or a separate reconciliation layer. 

Key capabilities include: 

  • Centralized access administration: Streamline access management for users, groups and system resources, with the option to delegate bounded authority without granting unrestricted administrative privileges. 

  • Policy-based command validation: Validate administrative commands against defined policies before execution, helping prevent unauthorized changes, user errors, and misconfigurations. 

  • Consistent application-level enforcement: Apply RACF-based access controls across critical application environments as systems and requirements evolve. 

  • Operational visibility: Use structured logging and notifications to gain a clearer view of significant access-related activity and changes. 

  • Access assessment: Evaluate whether entitlements remain warranted and simulate proposed changes against a copy of the RACF database before modifying production. 

  • Native Python access to RACF data: Query RACF information and use structured results in dashboards, analyses and existing enterprise security tools. 

Together, these capabilities help organizations move from fragmented, reactive administration toward continuous access governance—making it easier to identify unnecessary privilege, enforce policy earlier and help reduce access risk before it becomes a larger security issue. 

Turning access governance into an operational advantage 

IBM zSecure Access helps organizations: 

  • Reduce risk by validating commands and assessing entitlement changes before they reach production 

  • Improve visibility into who has access, how that access is used, and whether it remains appropriate 

  • Identify and clean up unused or over-provisioned access 

  • Simplify routine administration and reduce manual coordination 

  • Help prevent access misconfigurations that can affect application security, trust and availability 

The value goes beyond simpler administration. Stronger access governance helps organizations reduce opportunities for compromise, protect trust in critical systems, and continuously strengthen their security posture as threats evolve. 

Looking forward 

IBM plans to design and deliver AI, agentic, and expanded interface capabilities to IBM zSecure Access, furthering its mission to modernize RACF administration and provide intelligence and automation to augment deep z/OS expertise. 

Getting started and availability 

By unifying RACF administration, policy enforcement, access visibility and recertification, IBM zSecure Access can help organizations continuously reduce access risk while simplifying the protection of their most critical systems. 

IBM zSecure Access will be generally available from 18 September 2026. 

0 comments
1 view

Permalink