Internet References

    • https://www.ibm.com/docs/en/zos

      Description: All z/OS System documentation for each level provided free of charge by its builder. For those who like complete libraries of any professional subject. Several years just to read a level.

      Date: 17-08-2021

      https://www.redbooks.ibm.com/

      Description: 20 years ago getting an IBM redbook was a career milestone for any mainframe environment professional. Today you can access them and a much more condensed and practical version of the different aspects that it deals with. They are written by professionals who have read all the manuals on a subject, implemented it in real environments and with the conclusions they wrote a redbook with the key information. This information is basic for professionals in charge of data security.

      Date: 17-05-2021

      LINK --> Descripción curso online VA080 para auditores TI

      Description: Another possibility is to follow our online course VA080 on IT auditing in z/OS environments for novice auditors and experts in the environment. More than 30 hours of videos and thousands of hours of knowledge. Download the PDF that describes the course.

      Date: 17-08-2021

      LINK --> La checklist de Auditoría z/OS de ISACA

      Description: The objective of the z/OS Audit review is to provide management with an independent assessment relating to the controls addressing the configuration and security of the z/OS operations systems with the enterprise’s computing environment.

      Date: 17-08-2021

    • LINK --> Descripción de los STIG de la DISA para auditores TI

      Description: In this presentation that we made at a conference for Mainframe users in 2010, we already explained the state of Regulatory Compliance adapted to Mainframe z/OS platforms. The American DISA STIGs are still the most technological controls that existed at that time. In this presentation we explained its structure and the different aspects it covers.

      Date: 17-08-2021

      LINK --> Visualizador de los STIG de la DISA para auditores TI

      Description: Compilation of all American DISA STIGs for z/OS environments. Any company that needs to contract with the American administration has to show its degree of compliance. There is STIG for all the systems and software that the US administration has contracted.

      Date: 17-08-2021

      • https://www.go2bsecure.com/audihack/

        Description: The Bsecure VA060 online course in its 2022 version is the best hacking course in z/OS environments for technicians and Security managers in z/OS environments. It is a totally Online course in Spanish taken by hundreds of professionals since its first version ten years ago.

        Date: 17-6-2022

        LINK --> ibm-mainframe-security book

        Description: A book that shows us a small part of what has to be taken into account in the security of a mainframe with z/OS and RACF. The most important thing is the overview of that security.

        Date: 17-6-2022

      • LINK --> CICS pentest tool

        Description:CICSPAWN is an excellent tool to perform a penetration test in the CICS environment. It is a contribution of Ayoub Elaassal.

        Date: 17-02-2022

        LINK --> La Casa de John the Ripper

        Description:John the Ripper's house on github to install it in our environment, and have it work for us on those z/OS installations that still have the 8-position password implemented.

        Date: 17-02-2022

        LINK --> La mayor biblioteca de utilidades z/OS en Internet

        Description:cbttape.org is the github for unselfish contributions from experts on z/OS systems. There are thousands of utilities created by excellent z/OS experts over the years and shared with the mainframe community. Utilities created dozens of years ago still work like the first day. Many mainframe exploits are based on these utilities. As always, there is a dark side and a bright side.

        Date: 17-02-2022

        LINK --> Utilidades para RACF

        Description:A good starting point to have a true arsenal of tools with which to carry out a quick footprinting. This is a contribution from Jim Taylor to help RACF administrators.

        Date: 17-02-2022

        LINK --> Utilidades de Nigel Pentland

        Description:Nigel Pentland many years ago built his own RACF programs into the windows environment to help to RACF Administrators. He and Peter Goldis were the pioneers in built easy helping software for Administrators. Peter is retired and enjoy with his family but still there are any utilities in the Internet with his signature.

        Date: 17-02-2022

    • LINK --> Pill 3 - Challenges of the CISO before Mainframe - Retirement of knowledge (in Spanish).

      Description: Young professionals don't see a future for them. We have taken early retirement for professionals with enough experience fifteen years ago and we sent them home. Now they have retired, leaving one of the largest knowledge gaps in critical mission infrastructures in Information Technology. We analyze the impact on the security and availability of data that is the responsibility of CISOs.

      Date: 17-3-2020

      LINK --> Pill 4 - CISO Challenges before Mainframe - Myth 1- The most secure IT platform (in Spanish).

      Description: There is a false sense of security for many CIOs and even CISOs about z/OS mainframe platforms. The further away you are from the platform, the more sense of security you have. The problem is that it is in that distance where the budgets for the different Departments and Areas are managed. Expressions such as: -"With all that we are spending on firewalls, anti-intrusion software, log correlators..., are you now saying that there could be serious security problems on the Mainframe? Its maintenance costs us more than xx million Euros. With this cost, it is understood that it is safe, and also... We have already made sure that nobody comes in from outside to do what they shouldn't. We dismantle that myth with facts and data. The mainframe is an environment technological like any other.Perhaps the most securizable of the technologies that treat data, but managed by humans who make human errors.

      Date: 17-4-2020

      LINK --> Pill 5 - CISO Challenges before Mainframe - Myth 2 - Serious incidents and guilty profiles (in Spanish).

      Description: There are many CIOs and even CISOs who believe that one of the fundamental pillars of security on the z/OS mainframe platform is complexity. This leads them to believe that only technicians with extensive training and extensive experience in the environment could generate data security incidents. In this pill we get you out of the error based on verifiable data. It is a complex infrastructure to achieve 99.99% data availability, but it is not so complex to exploit known vulnerabilities.

      Date: 17-5-2020

      LINK --> Pill 8 - CISO Challenges before Mainframe - Myth 5 - Outsourcing solves everything (in Spanish).

      Description: Given the complexity of a critical infrastructure, such as the z/OS mainframe. Taking into account the difficulty of finding professionals with sufficient knowledge and experience in a critical environment. One of the options most used by business users responsible for the platform is to outsource multiple activities necessary for its maintenance and improvement. We analyze whether it is true, as many companies believe, that outsourcing will solve all their problems with data security and availability.

      Date: 17-8-2020

      LINK --> Pill 10 - CISO Challenges before Mainframe - Regulatory Compliance (in Spanish).

      Description: We analyze how the pressure of compliance with regulatory frameworks affects a mission-critical infrastructure such as mainframe technology. We list the main difficulties that CISOs encounter to comply with all the periodic reviews of risk management. We take the approach that we believe is most reasonable given the current situation.

      Date: 17-10-2020

      • LINK --> ZDNET

        Description: One of the leading sources of mainframe news.

        Date: 17-6-2022

        LINK --> PC World

        Description: Search for the word "mainframe" to get the news.

        Date: 17-6-2022

      • LINK --> Guide Share Europe

        Description:GSE is the oldest computer user group and still active in the US. In the early days of computing SHARE was founded by the aerospace industry corporate users of IBM mainframe computers in 1955. GUIDE (Guidance of Users of Integrated Data-Processing Equipment) followed a year later.

        Date: 17-05-2022

        LINK --> https://www.share.org/

        Description:Since 1955, SHARE has produced events that deliver unmatched education and access to the global enterprise computing community. In-person events and webcasts provide participants with unique education, access to innovation and the opportunity to connect with peers and recognized subject matter experts.

        Date: 17-05-2022

        LINK --> https://www.openmainframeproject.org/

        Description:The Open Mainframe Project is intended to serve as a focal point for deployment and use of Linux and Open Source in a mainframe computing environment. The Project intends to increase collaboration across the mainframe community and to develop shared tool sets and resources.

        Date: 17-05-2022

        LINK --> https://www.zowe.org/

        Description:Zowe is an integrated and extensible open source framework for z/OS. Zowe, like Mac OS or Windows, comes with a set of APIs and OS capabilities that applications build on and also includes some applications out of the box.

        Date: 17-05-2022

    • LINK --> mvsforums

      Description: One of the leading sources of mainframe news.

      Date: 17-6-2022

      LINK --> Narkive

      Description: In security, the forums are mines where you can search and find the gold.

      Date: 17-6-2022

      LINK --> RACF Listserv

      Description: In this list is all the knowledge about the implementation and management of the RACF. The world's leading experts write in it.

      Date: 17-6-2022

      LINK --> bit.listserv

      Description: In security, the forums are mines where you can search and find the gold.

      Date: 17-6-2022

      LINK --> reddit.com

      Description: In security, the forums are mines where you can search and find the gold.

      Date: 17-6-2022

      LINK --> ibmmainframer

      Description: In security, the forums are mines where you can search and find the gold.

      Date: 17-6-2022

      LINK --> zmainframes

      Description: In security, the forums are mines where you can search and find the gold.

      Date: 17-6-2022

      LINK --> mainframes.com

      Description: In security, the forums are mines where you can search and find the gold.

      Date: 17-6-2022

      LINK --> mainframegurukul

      Description: In security, the forums are mines where you can search and find the gold.

      Date: 17-6-2022

      LINK --> cobolforo

      Description: In security, the forums are mines where you can search and find the gold.

      Date: 17-6-2022

      LINK --> ibmmainframes.com

      Description: IBMMAINFRAMES.com is an independent software organization, started in 1998 in Chennai by a team of 25 unique-minded mainframe professionals to make a communication channel among worldwide mainframe programmers by providing technical support, training, and B2B software products.

      Date: 17-6-2022

      LINK --> ibmmainframeforum

      Description: In security, the forums are mines where you can search and find the gold.

      Date: 17-6-2022

    • LINK --> Bsecure

      Description: Bsecure - The Mainframe & Security Company, is a Consultant specialized in Information Technology in large International Companies. With more than 30 years of experience in hacking, security, auditing and Compliance in z/OS environments, we are a benchmark in modern services oriented to SOCs and Audit and Compliance Departments of our clients.

      Date: 17-6-2022

      LINK --> Stu Henderson

      Description: The Henderson Group provides security reviews, implementation and planning assistance, technical support, and audit response service for security over a wide range of platforms, software, and networks.

      Date: 17-6-2022

      LINK --> Vanguard Integrity Professionals

      Description: Founded in 1986 to help customers safeguard mission critical applications and data, Vanguard Integrity Professionals is the largest independent provider of enterprise security software for addressing complex security and regulatory compliance challenges. Annually host one of the industry's largest conferences on security in z/OS environments

      Date: 17-6-2022

      LINK --> Robert Hansel

      Description: RSH Consulting Inc., owned by Robert Hansel offers sound, practical advice and assistance to IBM z/OS administrators, technicians, and auditors seeking to enhance the cybersecurity of their mainframe systems by fully exploiting all the capabilities and latest innovations in RACF.

      Date: 17-6-2022