Pages

Friday, July 5, 2013

CA GovernanceMinder - Import/Export From IBM Mainframe Top Secrete (TSS)

Import/Export From IBM Mainframe Top Secrete

 

Overview

TSS is a security component for IBM mainframe computers that works together with the existing operating system to provide system security, resource access control, auditability, accountability and administrative control. As such, it is the main repository for users, roles and resources data on mainframe computers.

The main input to the Sage TSS import option requires downloading access data from TSS using the by generating a TSS List File, and transferring the generated text file to a location on the Windows system to which Sage has access. There is also a possibility to add enriched data about users attributes (for example, from the human resources department database).

The output is a Sage configuration, with TSS profiles appearing as Sage roles and with TSS groups appearing as Sage resources.

Import data from TSS into Sage

1. Create a TSS List File on the mainframe and transfer the file to a location that can be accessed by your Windows system.

JOB TSSUTIL

TSS LIST(ACIDS) DATA(ALL)

2. From within Sage DNA Data Management, from the Import menu on the menu bar, select Import from TSS.

The following window shows the TSS import window already completed:

image002

Importing from TSS

The following are instructions for filling in the fields:

Field

Description

Sage Files

Sage Configuration File

Enter the name and folder of the target Sage configuration. A Browse button is provided for convenience.

Users Database

Enter the name and folder of the target Sage users database. A Browse button is provided for convenience.

Resources Database

Enter the name and folder of the target Sage resources database. A Browse button is provided for convenience.

Options

TSS List File

Record the RACF platform name.

Profiles as Roles radio button

Activate radio button if Sage is to convert TSS Profiles to Sage roles.

Do not activate radio button if Sage is to not convert TSS Profiles to Sage roles.

Groups as Resources radio button

Activate radio button if Sage is to convert groups to resources.

Do not activate radio button if Sage is to not convert groups to resources.

TSS List File

Enter the path to the TSS list file copied to your Windows system.

Add ACL Entities check box

Mark Process Audit Cards check box to process Application Control Language (ACL) scripts.

Unmark Process Audit Cards check box not to process Application Control Language (ACL) scripts.

Supplementary HR file

Record the name of the file containing supplementary users data, if any.

1. Fill in the fields in the Importing

2. Click Convert to import.

If any errors result from the import process, then a Sage message appears. Check any errors in the SageTSSConverterXXX.log file located in the Sage Logs folder.

image004

TSS Error Message

The configuration is created in the target folder but is not automatically opened by Sage.

Types of reports that Sage ERM can generate

Note: all "suspected" objects are generated from a cross analysis of the access rights with the provided users' HR attributes.

Suspected issues are potentially a risk and should be reviewed and evaluated by the user.

Suspected Entities Reports
  1. Suspect Group Definition (Groups that are connected to users with no common HR attributes)                                                                                                        
  1. Suspected User Collector (User that collected access rights from previous positions)                                                                                               
  1. Suspected Dataset Collectible – Datasets that are linked to users with common no HR attributes                                                                                                        
  1. Suspect User-Dataset Connection – Links between users and dataset that are suspected base on the user’s HR attribute and other users that have access to the same dataset.                                                                                                    
  1. Suspect User-Group Connection  - Links between users and Groups that are suspected base on the user’s HR attribute and other users that have access to the same Group.                                                                                                                                                                                                    
  2. Suspect Group-Resource Connection                                                                                                    
  3. Dual User-Dataset Link  - User linked to a Dataset via a Group and directly                                                                                                  
  4. Dual Group-Dataset Link  - Groups linked to a Dataset via 2 different groups (hierarchies)
  1. Dual Group-Group Link    - Groups linked to a Group via 2 different groups (hierarchies)  
  1. Similar Group & Group Hierarchy – Groups that can be subgroups of other groups
  1. Groups For Almost Same Datasets  - Groups that are connected to the same datasets where some % of the datasets are the same                                                          
  1. Groups For Almost Same Users - Groups that are connected to the same sets within a % of # of users.                                                                                                                   
  1. Group Subsumed By Another (Same Datasets)       
  1. Group Subsumed By Another (Same Users)        
  1. Hierarchy Opportunity (Parent, Child)                                                                     
Similar Datasets Reports
  1. Overlapping Datasets (to users)                                                                                    
  2. Datasets Hierarchy Opportunity (Full, Partial)                                             
In/Out of pattern Reports
  1. User Almost Matches a Group – based on % of matching
  1. Dataset Almost Matches a Group    – based on % of matching  
  1. New Group Proposal  to users                                                                                                            
  2. New Dataset Proposal to users
Entities with many/few connections Reports

(note – this would also include orphan accounts, groups, resources)

  1. User with Many Direct Datasets                                                                                                
  2. User with Many Total Datasets
  1. User is a Member of Many Groups                                                                                                   
  2. User with Few Direct Datasets
  1. User with Few Total Datasets                                                                                                  
  2. User is Member of Few Groups
  1. Dataset with Many Direct Users                                                                                                
  2. Dataset with Many Total Users   
  1. Dataset Used by Many Groups                                                                                                    
  2. Dataset with Few Direct Users
  1. Dataset with Few Total Users                                                                                                  
  2. Dataset Used by Few Groups
  1. Group with Many Users                                                                                                           
  2. Group with Many Total Users
  1. Group with Many Datasets                                                                                                       
  2. Group with Many Total Datasets
  1. Group with Many Sub Groups                                                                                                       
  2. Group with Many Parent Groups
  1. Group with Few Users                                                                                                            
  2. Group with Few Total Users
  1. Group with Few Datasets                                                                                                        
  2. Group with Few Total Datasets   
  1. Group with Few Sub Groups                                                                                                        
  2. Group with Few Parent Groups       
  1. Dual Group-Group Link 
Business Policies Process

  1. Segregation of duty report  - Restrictions between Group to Group
  2. Segregation of duty report  - Restrictions between Dataset  to Dataset
  3. Segregation of duty report  - Restrictions between Group to Dataset
  4. Segregation of duty report  - Restrictions between HR data to Group
  5. Segregation of duty report  - Restrictions between HR data to Dataset
  6. Counter for User access limits reports on Groups
  7. Counter for User access limits reports on Datasets