RACF
The security manager for z/OS, which decides who may sign on, read a dataset, or run a transaction.
Also written Resource Access Control Facility, security manager
RACF, or Resource Access Control Facility, holds the security rules for a z/OS system. Every attempt to log on, open a dataset, run a transaction or issue a command is checked against it before it is allowed.
It keeps a database of three things: users, each with an identity and attributes; groups, which collect users together; and profiles, which describe resources and who may do what to them.
The model is deliberately indirect. Access is almost never granted to an individual. Instead a group is given access to a set of resources, and people are connected to the group. When someone joins a team they are added to a group and immediately have what they need; when they leave, removing them takes it all away at once. Managing access one person at a time does not scale past a handful of users.
Competing products exist. ACF2 and Top Secret do the same job, and all of them plug into z/OS through the same interface, so the concepts carry across.
Related terms
- RACF user IDA person or program's identity on the system. Short, unique, and the basis of every access decision.
- RACF groupA named collection of users, used to grant access to many people at once rather than one at a time.
- Dataset profileA security rule describing which datasets it covers and who is allowed to do what to them.
- Access levelHow much a user may do to a resource: read it, change it, or control it, with each level including the ones below.
- SAFThe interface z/OS and its subsystems use to ask the security manager whether something is allowed.
- PERMITThe command that grants or removes a user or group's access to a protected resource.