Best practices:PERMIT to PROFILE or directly on acid.

Document ID : KB000100664
Last Modified Date : 08/06/2018
Show Technical Document Details
Issue:
The ultimate goal it to authorize the user to DSN(CFZSRV).
 
This can be achieved by:
1.            PERMIT the user directly on their acid.
2.            Add a PROFILE acid that has been PERMITted to DSN(CFZSRV).
3.            Give the user NODSNCHK and NOVOLCHK attributes which is total overkill since it gives the user access to every dataset. This is not a best practice. Auditor frown up on this.
 
Best practices would be to permit the PROFILE and then attach the PROFILE to the users.
 
Permitting to an acid directly is not wrong.
 
Its just a matter of choice.
 
Resolution:
The ultimate goal it to authorize the user to DSN(CFZSRV).

This can be achieved by:
1.    PERMIT the user directly on their acid.
2.    Add a PROFILE acid that has been PERMITted to DSN(CFZSRV).
3.    Give the user NODSNCHK and NOVOLCHK attributes which is total overkill since it gives the user access to every dataset. This is not a best practice. Auditor frown up on this.

Best practices would be to permit the PROFILE and then attach the PROFILE to the users.

Permitting to an acid directly is not wrong. 

Its just a matter of choice.