Input/Output
Configuration
Data
Set
(IOCDS)
An
IOCDS
defines
the
logical
partitions
by
name,
allocates
I/O
resources
to
each
of
them,
and
specifies
the
security
characteristics
of
those
I/O
resources.
The
following
list
describes
the
security-relevant
parameters
of
each
type
of
IOCDS
source
statement.
Statement
Type
Discussion
ID
No
security-relevant
parameters.
RESOURCE
Assign
logical
partition
names
and
MIF
image
IDs
so
that
explicit
control
is
asserted,
and
maximum
checking
of
following
IOCDS
source
statements
is
enabled.
CHPID
v
Use
PARTITION
parameter
to
specify
which
logical
partition
each
channel
path
is
allocated
to.
v
Don’t
use
the
SHARED
parameter.
v
Don’t
use
REC
without
study
of
security
implications.
v
Specify
whether
the
channel
path
is
REConfigurable
,
and
specify
which
logical
partitions
are
to
have
access
(using
logical
partition
names
in
the
candidate
list).
v
Do
not
use
the
IOCLUSTER
keyword.
Use
of
this
keyword
will
enable
sharing
of
CHPIDs
by
partitions
within
the
named
cluster.
CNTLUNIT
Specification
of
the
PATH
parameter
must
be
accorded
care
so
that
a
secure
configuration
results.
IODEVICE
Specification
of
the
CUNUMBR
parameter
must
be
accorded
care
so
that
a
secure
configuration
results.
LPAR
Input/Output
Configurations
v
In
general,
I/O
devices
must
not
be
shared
by
logical
partitions,
since
they
can
be
used
to
pass
information
from
one
partition
to
another.
There
may
be
special
cases,
such
as
an
output-only
device
which
an
installation
may
consider
sharable
after
careful
review
of
any
related
security
risks,
and
defining
related
security
procedures
and
processes.
v
The
PCHID
Summary
Report,
Channel
Path
Identifier
(CHPID)
Summary
Report
and
I/O
Device
Report
produced
by
the
Input/Output
Configuration
Program
must
be
thoroughly
examined
by
the
Security
Administrator
for
indications
of
unwanted
sharing
or
reconfigurability
of
channels
and
devices.
v
A
thorough
review
of
the
actual
physical
connections/links
of
the
I/O
configuration
must
be
performed
to
establish
that
the
physical
configuration
is
identical
to
that
specified
in
the
IOCDS
source
file.
Specific
attention
should
be
given
to
devices
with
multiple
device
path
capability,
to
help
ensure
that
one
device
(or
control
unit)
does
not
(accidentally)
connect
to
more
than
one
partition’s
channel
paths.
v
All
IOCDSs
should
be
write-protected
except
for
the
few
minutes
during
which
they
are
actually
updated.
v
The
time
stamps
of
the
production-level
IOCDSs
should
be
recorded.
By
dragging
the
CPC
Icon
over
to
the
I/O
Configuration
task
under
the
CPC
B-8
PR/SM
Planning
Guide
Содержание Z9
Страница 1: ...System z9 Processor Resource Systems Manager Planning Guide SB10 7041 03...
Страница 2: ......
Страница 3: ...System z9 Processor Resource Systems Manager Planning Guide SB10 7041 03...
Страница 12: ...x PR SM Planning Guide...
Страница 18: ...xvi PR SM Planning Guide...
Страница 26: ...xxiv PR SM Planning Guide...
Страница 43: ...ZVSE ZVM Figure 1 1 Characteristics of Logical Partitions Chapter 1 Introduction to Logical Partitions 1 17...
Страница 54: ...1 28 PR SM Planning Guide...
Страница 126: ...2 72 PR SM Planning Guide...
Страница 195: ...Figure 3 23 Security Page Image Profile Chapter 3 Determining the Characteristics of Logical Partitions 3 69...
Страница 220: ...4 8 PR SM Planning Guide...
Страница 232: ...5 12 PR SM Planning Guide...
Страница 250: ...B 16 PR SM Planning Guide...
Страница 266: ...D 10 PR SM Planning Guide...
Страница 272: ...X 6 PR SM Planning Guide...
Страница 273: ......
Страница 274: ...Printed in USA SB10 7041 03...