Operations
task
list,
a
display
of
the
available
IOCDSs
will
be
generated.
Periodic
audits
should
be
made
to
assure
that
the
IOCDSs
have
remained
unchanged.
Activation
A
reset
profile
includes
information
for
activating
a
central
processor
complex
(CPC)
and
its
images
(logical
partitions).
v
In
the
reset
profile,
after
selecting
an
LPAR
IOCDS
(A0-A3)
deemed
valid
for
secure
operation
via
the
Input/Output
(I/O)
Configuration
task,
the
operating
mode
selected
must
be
Logically
partitioned.
v
Dynamic
I/O
changes
can
be
disabled
on
the
Dynamic
Page
of
the
Power-on
Reset
Notebook
displayed
during
Power
on
Reset
of
the
CPC.
Ensuring
the
’Allow
dynamic
changes
to
the
channel
subsystem
input/output
(I/O)
definition)’
is
not
selected,
disables
dynamic
I/O
for
the
CPC.
Globally
disabling
dynamic
I/O
configuration
narrows
the
control
of
the
I/O
configuration
control
parameter
to
only
controlling
a
logical
partition’s
reading
and
writing
of
IOCDS.
Dynamic
I/O
changes
should
be
disabled
as
described
above,
thereby
globally
disabling
dynamic
I/O
configuration.
v
Enabling
Workload
Manager
(found
on
the
Security
page
of
the
Image
Profile),
will
permit
the
sharing
of
I/O
resources
among
clustered
partitions
using
the
Intelligent
Resource
Director
(IRD)
clustering
technology.
Therefore,
Workload
Manager
(IRD)
should
not
be
enabled
in
a
secure
environment
without
a
thorough
review
of
the
security
implications.
See
for
more
information.
Control
Authority
v
A
logical
partition’s
initial
security
settings
are
set
in
the
image
profile
used
to
activate
it.
Afterwards,
the
change
LPAR
security
task
can
be
used
to
view
or
change
the
settings.
Changes
must
be
saved
in
the
profile
in
order
to
have
them
available
for
subsequent
use.
Security
settings
are
saved
by
the
system
across
activations
for
the
current
configuration.
Therefore,
if
the
same
configuration
is
used,
Security
settings
need
not
be
reentered
(but
should
be
checked).
Important
Note
The
default
values
for
the
LPAR
Security
parameters
are
not
appropriate
for
secure
operation,
and
must
not
be
specified.
v
Partition
control
authority
must
NOT
be
given
to
any
of
the
logical
partitions
in
a
secure
mode
of
operation.
Abuse
of
control
authority
by
a
program
executing
in
a
logical
partition
can
disrupt
the
processing
in
other
logical
partitions.
v
The
following
LPAR
Security
parameter
settings
are
required
for
a
secure
mode
of
operation:
–
ISOLATION
should
be
enabled
.
This
option
binds
the
partition’s
allocated
I/O
configuration
to
it,
even
when
a
Channel
Path
(CHPID)
is
in
an
offline
state.
An
overt,
auditable
operator
action
is
required
to
unbind
an
item
of
the
I/O
configuration
and
move
it
to
another
partition.
–
I/O
CONFIGURATION
CONTROL
should
be
disabled
for
every
partition
.
By
negating
this
option,
the
partitions
are
prevented
from
accessing
(read
or
write)
the
existing
IOCDS
data
sets,
or
dynamically
altering
the
current
I/O
configuration.
IOCDSs
can
be
a
means
to
surreptitiously
pass
data
between
partitions.
In
addition,
dynamic
alteration
of
the
current
I/O
configuration
can
result
in
a
partition
having
access
to
data
that
it
is
not
authorized
to
access.
Appendix
B.
Developing,
Building,
and
Delivering
a
Certified
System
B-9
Summary of Contents for Z9
Page 1: ...System z9 Processor Resource Systems Manager Planning Guide SB10 7041 03...
Page 2: ......
Page 3: ...System z9 Processor Resource Systems Manager Planning Guide SB10 7041 03...
Page 12: ...x PR SM Planning Guide...
Page 18: ...xvi PR SM Planning Guide...
Page 26: ...xxiv PR SM Planning Guide...
Page 54: ...1 28 PR SM Planning Guide...
Page 126: ...2 72 PR SM Planning Guide...
Page 220: ...4 8 PR SM Planning Guide...
Page 232: ...5 12 PR SM Planning Guide...
Page 250: ...B 16 PR SM Planning Guide...
Page 266: ...D 10 PR SM Planning Guide...
Page 272: ...X 6 PR SM Planning Guide...
Page 273: ......
Page 274: ...Printed in USA SB10 7041 03...