Resource Access Control Facility

RACF, short for Resource Access Control Facility, is an IBM software product. It is a security system that provides access control and auditing functionality for the z/OS and z/VM operating systems. RACF was introduced in 1976.

It fulfills the main features:

  • Identification and verification of a user via user id and password check (authentication)
  • Identification, classification and protection of system resources
  • Maintenance of access rights to protected resources (authorization)
  • Control the means of access to protected resources
  • Logging of accesses to a protected system and protected resources (auditing)

RACF establishes security policies rather than just permission records. It can set permissions for file patterns — that is, set the permissions even for files that do not yet exist. Those permissions are then used for the file (or other object) created at a later time.

RACF has continuously evolved to support such modern security features as digital certificates/public key infrastructure services, LDAP interfaces, and case sensitive IDs/passwords. The latter is a reluctant concession to promote interoperability with other systems, such as Unix and Linux. The underlying zSeries hardware works closely with RACF. For example, digital certificates are protected within tamper-proof cryptographic processors. Major mainframe subsystems, especially DB2 Version 8, use RACF to provide multi-level security (MLS).

Its primary competitors have been ACF2 and TopSecret, both now produced by CA, Inc.

Famous quotes containing the words resource, access, control and/or facility:

    The waste of plenty is the resource of scarcity.
    Thomas Love Peacock (1785–1866)

    Whilst the rights of all as persons are equal, in virtue of their access to reason, their rights in property are very unequal. One man owns his clothes, and another owns a country.
    Ralph Waldo Emerson (1803–1882)

    America is neither free nor brave, but a land of tight, iron- clanking little wills, everybody trying to put it over everybody else, and a land of men absolutely devoid of the real courage of trust, trust in life’s sacred spontaneity. They can’t trust life until they can control it.
    —D.H. (David Herbert)

    Virtue rejects facility to be her companion.... She requires a craggy, rough and thorny way.
    Michel de Montaigne (1533–1592)