IBM Security Z Security

Security for Z

Join this online user group to communicate across Z Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
Expand all | Collapse all

Cleanup of Inactive Permissions - View Permission create date

  • 1.  Cleanup of Inactive Permissions - View Permission create date

    Posted Mon April 17, 2023 01:21 PM
    Edited by Linnea Sullivan Mon May 01, 2023 02:39 PM

    I am attempting to clean up my RACF DB of permissions that have not been used in a year.    I started with AM.3 (PERMIT) and I can run a report of permissions that have been used before but have no activity in a year.     But I also see permissions that have never been used that need to be cleaned up as well.   However using the TSO screens I can query on the create date of the profile.   But that does not help, since the profile could have been created years ago, and the permission was granted last week.   I don't want to delete recently provisioned access.

    Do we have the ability on AM.3 to display the date the permission was granted to the profile?

    Update 5/1/23:  Will still like a reply from IBM if possible if the solution for a permission create date already exists, however we think we have developed a process to take the profile in the Access Monitor data and "mine" the data in Command Logger to see if the permission was granted within x number of days to determine if the permission was granted recently.




    ------------------------------
    Linnea Sullivan
    ------------------------------



  • 2.  RE: Cleanup of Inactive Permissions - View Permission create date

    Posted Thu May 04, 2023 08:36 AM

    Blunt answer: Nope.

    RACF doesn't record the PERMIT date anywhere. You would indeed need to correlate with the CKXLOG or with the Command Verifier CAT(Command Audit Trail).
    And sorry for the delayed response. 



    ------------------------------
    Guus Bonnes
    ------------------------------