Mainframe evidence practice
Mainframe Security and Forensics for Enterprise Matters
Forensic examination and independent security assessment of IBM z/OS mainframes: RACF and ACF2 identity records, SMF audit analysis, IMS and DB2 for z/OS access review and CICS transaction evidence for banking, insurance, government and enforcement matters.
The engagement
Security and audit evidence from z/OS systems
IBM Z environments can hold central transaction, identity, application and security records for banks, insurers, government agencies and other enterprises. When a matter reaches those systems, the audit surface differs from a Windows or Linux examination. System Management Facility, or SMF, writes typed records for configured and supported events across logical partitions. Identity evidence may come from RACF, ACF2 or Top Secret, while application evidence may include records from IMS, DB2 for z/OS and CICS.
The examination reviews the SMF record for the LPARs in scope, reconciles it against the RACF or ACF2 database exports, correlates access decisions against IMS, DB2 and CICS transaction records where those are audited, and states what the mainframe evidence shows about the specific matter. The report identifies the exact record types, audit configuration and gaps so a mainframe-literate examiner can pull the same SMF record type and reach a reproducible conclusion.
The practice supports enterprise insider matters, federal enforcement matters reaching bank and insurance mainframes, breach-response work when a mainframe is in scope, IBM zSecure and DB2 audit review, and independent RACF or ACF2 security assessments where a change in security posture is at issue. Reports are written for counsel, compliance and enforcement audiences, not for the mainframe operations team.
Scope
SMF audit forensics
Analysis of System Management Facility records across LPARs: type 30 job and step records, type 42 storage records, type 80 RACF audit records, type 81 RACF initialization, type 92 file activity, type 100 through 102 DB2 audit, type 110 CICS, type 119 TCP/IP and the surrounding record types relevant to the matter.
RACF and ACF2 identity analysis
Analysis of RACF or ACF2 database exports and IRRDBU00 unloads for RACF: user IDs, groups, connections, general resource profiles, dataset profiles, access levels and change history. Coverage of Top Secret where in scope.
IMS and DB2 for z/OS access review
IMS security-profile and command audit review, DB2 for z/OS SQL audit trace review with the record types the site actually enabled, and application-layer access analysis where the record supports it.
CICS transaction and terminal audit review
CICS transaction and terminal audit review, sign-on and command records, and reconciliation against SMF type 110 records.
Independent RACF or ACF2 security assessment
Independent review of the external-security-manager configuration: sensitive resource protection, dataset-profile posture, privileged-user population and change history, SETROPTS or GSO parameter state and the class-descriptor-table posture.
zSecure and DB2 audit tooling review
Review of IBM Security zSecure Admin and zSecure Audit output, DB2 audit trace output and third-party tooling output where relevant. The report distinguishes tool output from the underlying record and cites both.
Reporting for enterprise, enforcement and compliance audiences
Written reports for counsel, compliance and enforcement audiences stating what the mainframe evidence shows about the specific allegation, insider incident or enforcement question.
Methodology
How a mainframe forensics matter runs
-
Retention and LPAR scoping
Retention letter, conflict check, and a scope note stating which LPARs, which SMF record types and which external security manager the examination will address.
-
Preservation of SMF and identity records
Coordinated preservation of SMF records for the review period, RACF or ACF2 database unloads and application audit exports from IMS, DB2 for z/OS and CICS where in scope.
-
Reconciliation and analysis
SMF audit correlated against RACF or ACF2 identity, application audit and change management. Analysis stated in the units the matter needs.
-
Report and testimony
A written report and, where the matter reaches it, deposition and trial testimony bounded by the report.
Evidence commonly examined
Evidence reviewed
- SMF records for the LPARs and review period in scope
- RACF IRRDBU00 unloads and ACF2 database extracts
- IMS security profile exports and command-audit records
- DB2 for z/OS audit-trace exports with the record types the site enabled
- CICS transaction, terminal and sign-on audit records
- SETROPTS or GSO parameter records and class-descriptor-table records
- zSecure Audit and zSecure Admin exports where the tool is in place
What you can expect
What you receive
- Written report on the mainframe evidence for the matter
- SMF-record-type appendix stating which types were audited and which were not
- RACF or ACF2 access-decision appendix with user, resource and access-level detail
- IMS, DB2 for z/OS or CICS appendix where those systems are in scope
- Deposition and trial testimony bounded by the report
- Demonstratives sourced to SMF records and identity-database exports
Frequently asked
Common questions
Does the analysis use native z/OS records?
Yes. The scope can include direct SMF record examination, RACF or ACF2 database analysis and DB2 for z/OS audit review. The examiner works from the available native records and documented exports, not a rewritten summary alone.
Which external security managers do you cover?
RACF is the primary coverage. ACF2 is covered where the site uses it. Top Secret is covered where the site uses it. The report states which manager the site actually runs and adapts the analysis accordingly.
How do you handle a site that did not audit the record type the matter needs?
Where the SMF configuration did not audit the record type in question, the report says so and identifies which record types were and were not written. The scope of what can be concluded is bounded by the audit configuration the site actually ran, and that boundary is stated on the record.
Do you address DB2 for z/OS, IMS and CICS, or just RACF and SMF?
DB2 for z/OS audit-trace records, IMS security-profile exports and CICS transaction and sign-on audit records are addressed where the matter reaches them. The report states which application security managers were in scope, which record types were reviewed and what the review actually shows.
How does the mainframe evidence match up with the identity and application record?
SMF audit is reconciled against RACF or ACF2 identity, IMS or DB2 for z/OS application audit and change-management records for the review period. Where records reconcile, the report says so. Where they do not, the report states the gap and its scope.
Related capabilities
Related services
Talk with an examiner
Discuss the matter and the next step.
Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.
24/7 hotline: 1-800-868-8189