Skip to content
Security

RACF

The security manager for z/OS, which decides who may sign on, read a dataset, or run a transaction.

Also written Resource Access Control Facility, security manager

RACF, or Resource Access Control Facility, holds the security rules for a z/OS system. Every attempt to log on, open a dataset, run a transaction or issue a command is checked against it before it is allowed.

It keeps a database of three things: users, each with an identity and attributes; groups, which collect users together; and profiles, which describe resources and who may do what to them.

The model is deliberately indirect. Access is almost never granted to an individual. Instead a group is given access to a set of resources, and people are connected to the group. When someone joins a team they are added to a group and immediately have what they need; when they leave, removing them takes it all away at once. Managing access one person at a time does not scale past a handful of users.

Competing products exist. ACF2 and Top Secret do the same job, and all of them plug into z/OS through the same interface, so the concepts carry across.

Browse all 115 terms

Learn this properly.

Use RACF for real in Mainframe101, in your browser, with Zed beside you. Join the waitlist.

Early access and updates. No spam, unsubscribe any time.