Creating a DEFAULT security group with limited access

Document ID : KB000091896
Last Modified Date : 25/04/2018
Show Technical Document Details
Question:
We are installing SYSVIEW on all of our LPARS (64 total). We want a DEFAULT security group with limited access.
Q1) Can we control the options in the DEFAULT group using a parm instead of edits in the DEFAULT group ?
Q2) Can we copy the DEFAULT group to other LPARS once it is modified ( if we cant use a a parm)?
Answer:
A1) There are no parameters to control the DEFAULT group's access. Updating it through the SECURITY command is the only option. Once you have the DEFAULT group customized on one LPAR, you can copy the DEFAULT group into other security files using the GSVUSECC sample JCL contained in the CBN4BSAM data set (CNM4BSAM is the SMP/E target DDDEF).
A2)  For LPARs with shared DASD, the security file can be shared across LPARs. If you are going to share the security file across multiple LPARs, you might want to look at the SVWXSECC PARMLIB member to set up a process to keep the cached security data in synch when an update to the security file is made.