A large European Bank
Customer Project: Automating and Integrating Network and Application Security
IT auditors and the business organization staff of the bank agreed that for the 40,000 users of its client/server applications, IMS applications, other mainframe systems and its Windows network, the user administration systems currently in use were not providing the security required by the bank and were demanding too much administrator time.
Additionally, the in-house developed application security system offered only limited administration capabilities not only making administration a tedious chore but also endangering the bank's security: monitoring of current user access rights was difficult leading to potential accumulation of access rights. Indeed, application security administration for the IMS mainframe systems and the Windows-based client/server applications was being performed manually or by using self-written scripts.
The bank chose SAM as a standard software solution enabling it to integrate network and application security, administer both in a uniform way, and to automate administrative tasks. SAM offers broad functional support for Windows and RACF administration and provides all the necessary customization means for efficient management of application security. As it was decided from the start that, later down the road, user administration would be role-based, SAM's uniquely strong role-based administration capabilities led it to become the clear choice for the bank. Its ability to combine rules and roles promised great potential for a high degree of automation.







