• Español Español Spanish es
  • English English English en
  • Français Français French fr
  • Shopping Cart Shopping Cart
    0Shopping Cart
SIXE
  • Emergency support
  • Services
    • Technical Support
      • IBM Power
      • Ubuntu Pro with SIXE UP
      • Kubernetes
      • Openstack
      • Red Hat (RHEL)
      • SUSE
      • SAP
      • Ceph
      • IBM Storage
      • Databases
        • DB2
        • Informix
        • MariaDB / PostgreSQL
    • Migrations
      • To AIX from Red Hat or z/OS
      • To Linux
      • To Ubuntu from Red Hat and SUSE
      • To Red Hat OpenShift From VMWare
      • To OpenStack from VMWare and HyperV
      • To Proxmox VE from VMWare
    • Consulting & Strategy
      • Technology radar service
      • Sustainable technology
      • Ceph
      • DRP
      • vCTO
  • Infra
    • Servers
      • IBM LinuxOne 5 servers
      • IBM Power11
      • Supermicro
      • Dell
      • Lenovo
    • Storage
      • Ceph
      • IBM Storage FlashSystems
      • IBM Storage Scale (GPFS)
      • IBM Storage Fusion
      • Backup
        • IBM Storage Defender: Data Resilience & Ransomware Protection
        • Bacula
        • Trilio
    • Workloads
      • Containers
      • Virtual machines
      • Private Cloud
      • Databases
      • IBM Software
  • Cybersecurity
    • IT Security
      • Monitoring and Response (SIEM & SOAR)
        • Wazuh
        • IBM QRadar
      • Information protection (IRM and DLP)
        • Sealpath
      • IBM security tools
        • IBM PowerSC
    • OT Security
      • Claroty
      • Industrial Device Integrity and Security with Tenable OT (Indegy ICS)
      • Industrial & IoT cybersecurity solution with Indegy ICS and QRadar
  • AI ✨
    • AI agents for companies
    • On-Premise AI Inference
    • Training
    • Automation service
    • Docling
    • Ceph for AI and HPC
    • WatsonX
  • Training
    • Linux | AIX | IBM i
      • Linux
      • AIX
      • IBM i | i2040
      • PowerVM
      • PowerHA
    • Iaas & PaaS ☁️
      • OpenShift
      • Docker + K8s
      • KVM and oVirt (RHEV)
      • VMWare ESXi & vSphere
      • Red Hat Ansible
      • Foreman
    • Infra & Data
      • OpenStack
        • Deployment & Administration
        • Maintenance & Upgrades
        • Production & VMware Migration
      • CEPH
        • Deployment and administration
        • Advanced
        • Expert (Production Engineering)
      • Informix
      • Storage
      • DB2
    • IBM Security
      • IBM QRadar
      • Cybersecurity analyst
      • IBM Guardium
    • Official training
      • Official IBM Trainings
      • Canonical Course Catalog
      • Tailor-made training
  • About us
  • Contact us!
  • Menu Menu
Canonical business partner

Find other courses

×

Browse by field of study

IBM
🖥️ Mainframe & z/OS
z/OS 47CICS 9RPG 2DB2 38
📊 Data & Analytics
IBM Planning Analytics 4Infosphere 32BigInsights 7Datacap 12
🤖 AI & Automation
Watson 6IBM AI 15IBM AI 15
☁️ Cloud & Infrastructure
Cloud Management 4SmartCloud 5AIX 18IBM i 15IBM Storage 7Linux 15
🔐 Security 5
📁 Content Management
FileNet 14Content Navigator 7Case Manager 9Case Foundation 12Enterprise Records 8
⚙️ Development & Middleware
Integration Bus 3API Connect 6Rational 13DataPower 5Operational Decision Manager 8IBM Decision Server 4
💼 Business & Processes
Business Process Manager 29Sterling 15Curam 12TRIRIGA 5Operations Analytics 3IBM Algo One 17
Canonical / Ubuntu
🛠️ System Administration 4🔄 Automation 2🛡️ Cybersecurity 2☁️ Cloud 2📦 Containers 1🤖 AI 2💻 Virtualization 2
HashiCorp
🏗️ Terraform 3🔒 Vault 1
AI & Automation
⚡ N8N 2⚡ Zapier 2

Search by technology

  • AI
    • N8N
    • Zapier
  • HashiCorp
    • Terraform
    • Vault
  • Official Canonical Ubuntu training
    • AI
    • Automation
    • Containers
    • Cybersecurity
    • OpenStack Cloud
    • System administration
    • Virtualization
  • Official IBM Training
    • AIX
    • API Connect
    • Aspera
    • BigInsights
    • BladeCenter
    • Blockchain
    • Business Process Manager
    • Case Foundation
    • Case Manager
    • CICS
    • Cloud Management
    • Content Navigator
    • Curam
    • Datacap
    • DataPower
    • DB2
    • Enterprise Records
    • FileNet
    • IBM AI
    • IBM Algo One
    • IBM Cognos Analytics Training | BI Reporting Courses
    • IBM Decision Server
    • IBM Disk Systems
    • IBM Flash Storage
    • IBM i
    • IBM Planning Analytics
    • IBM Power Systems
    • IBM PureData Systems
    • IBM Security
    • IBM Storage
    • IMS
    • Informix
    • Infosphere
    • Instana
    • Integration Bus
    • Linux
    • Linux on IBM Power Systems
    • Miscellaneous
    • Open Platform
    • OpenPages
    • Operational Decision Manager
    • Operations Analytics
    • PowerHA
    • Rational
    • RPG
    • SmartCloud
    • Spectrum Suite
    • SPSS
    • Sterling
    • Tivoli
    • TRIRIGA
    • Turbonomic
    • Watson
    • WebSphere
    • z/OS
  • Wazuh

Implementing RACF Security for CICS/ESA and CICS/TS

4.375,00€

This course teaches you how to implement security for your CICS systems using RACF as the external security manager. The lecture material will first explain the implementation tasks for a single-region CICS system and then extend the scope to MRO- or ISC-connected multiregion CICS systems. In the classroom you will learn both the CICS and RACF definitions necessary to establish effective security controls for CICS. You will learn how to:

  • Protect CICS system resources so that CICS itself has access but other users, such as TSO users or batch jobs, are denied access.
  • Define CICS terminal users to RACF and restrict the CICS regions to which these users will be allowed to sign on.
  • Control access to individual CICS transactions.
  • Control access to CICS application resources accessed by these transactions.
  • Control execution of CICS system programmer interface (SPI) commands used within transactions.
  • Control access to installation-defined resources used to support application-specific security requirements.
  • Control access to CICS transactions and resources when two or more CICS address spaces are connected to enable use of the CICS transaction routing and function-shipping mechanisms.

You will learn about the wide variety of mechanisms that can be used to initiate transactions within CICS and the techniques for imposing security controls on each of these mechanisms. These mechanisms include the connections to CICS using Advanced Program-to-Program Communication (APPC) either from CICS client or server products on other platforms or from other products that support APPC. You will also explore the security interface between CICS, RACF, and DB2 and learn how RACF can be used to secure CICSplex System Manager, one of the elements provided with CICS Transaction Server for z/OS.

You will have many opportunities to apply what you have learned in the classroom with hands-on lab exercises in which you actually set up the definitions in both CICS and RACF. The hands-on lab begins with exercises where you will familiarize yourself with the CICS and RACF lab environment. In the lab exercises you start with a CICS address space that has no security. First, you will protect your CICS region resources. In subsequent lab exercises, you will set up user sign-on security, protect transactions, and set up resource-level security and SPI command security. In the last lab exercise, you establish security between a terminal-owning region (TOR) and an MRO-connected application-owning region (AOR).

SKU: 208. Category: z/OS
  • Description

Description

At SIXE we have been providing official IBM training around the world for over 12 years. Get the best training from our specialists in Europe. We have important discounts and offers for two or more students.

Course details

IBM course code: ES84GCategory: z/OS / RACF
Delivery: Online & on-site**Course length in days: 5

Target audience

This course is for security personnel and CICS support personnel responsible for designing, implementing, or administering RACF security for CICS Transaction Server systems.

Desired Prerequisites:

You should be familiar either with:

  • RACF (perhaps as a security administrator) or with CICS (perhaps as a member of your CICS technical support staff).

It is not assumed or necessary that you already be familiar with both RACF and CICS.

Instructors

The great majority of the IBM courses we offer are taught directly by our engineers. This is the only way we can guarantee the highest quality. We complement all the training with our own materials and laboratories, based on our experience during the deployments, migrations and courses that we have carried out during all these years.

Added value

Our courses are deeply role oriented. To give an example, the needs for technology mastery are different for developer teams and for the people in charge of deploying and managing the underlying infrastructure. The level of previous experience is also important and we take it very seriously. That is why beyond (boring) commands and tasks, we focus on solving the problems that arise in the day to day of each team. Providing them with the knowledge, competencies and skills required for each project. In addition, our documentation is based on the latest version of each product.

Agenda and course syllabus

Day 1

  • Welcome, course introduction, and administration
  • Unit 1 – CICS overview
  • Exercise 1 – CICS familiarization
  • Unit 2 – RACF overview
  • Exercise 2 – RACF familiarization

Day 2

  • Unit 2 lab review
  • Unit 3 – Protecting the CICS region
  • Exercise 3 – Protecting the CICS region
  • Unit 4 – Sign-on security
  • Exercise 4 – Sign-on security

Day 3

  • Unit 5 – Transaction security
  • Exercise 5 – Transaction security
  • Unit 6 – CICS resource and SPI command security
  • Exercise 6 – CICS resource security and SPI command security

Day 4

  • Unit 7 – CICS intercommunication bind and link security
  • Unit 8 – CICS intercommunication conversation security

Day 5

  • Lab Review
  • Unit 9 – Securing CICSPlex SM
  • Unit 10 – Planning for implementation
  • Unit 11 – CICS and DB2 security
  • Unit 12 – CICS Web Services security

Do you need to adapt this syllabus to your needs? Are you interested in other courses?  Ask us without obligation.

Locations for on-site delivery

  • Austria: Vienna
  • Belgium: Brussels, Ghent
  • Denmark: Cophenhagen
  • Estonia: Tallinn
  • Finland: Helsinki
  • France: Paris, Marseille, Lyon
  • Germany: Berlin, Munich, Cologne, Hamburg
  • Greece: Athens, Thessaloniki
  • Italy: Rome
  • Louxemburg: Louxembourg (city)
  • Netherlands: Amsterdam
  • Norway: Oslo
  • Portugal: Lisbon, Braga, Porto, Coimbra
  • Slovakia: Bratislava
  • Slovenia: Bratislava
  • Spain: Madrid, Sevilla, Valencia, Barcelona, Bilbao, Málaga
  • Sweden: Stockholm
  • Turkey: Ankara
  • United Kingdom: London

Related products

  • TCP/IP for z/OS Implementation Workshop

    4.375,00€
    Add to cart Add to cart Nº de alumnos Show Details Show Details Show Details
  • IBM System z Parallel Sysplex Operations

    3.075,00€
    Add to cart Add to cart Nº de alumnos Show Details Show Details Show Details
  • Parallel Sysplex Implementation Workshop

    4.375,00€
    Add to cart Add to cart Nº de alumnos Show Details Show Details Show Details
  • z/OS JES2 Operator Training

    3.075,00€
    Add to cart Add to cart Nº de alumnos Show Details Show Details Show Details

Blog!

  • IBM QRadar, G2 Leader in SIEM, UEBA, NTA and IR 2026
  • EDR beyond Windows: protect Linux, AIX & IBM i
  • db2 formacion oficial sixe ibm
    Your team is doing manually what Db2 12 already handles
  • OWASP API Security Top 10 vs IBM API Connect
  • Informix 2026: v15, watsonx and 12.10 end-of-support

Contact us!

Request a demo

Contact form

Become a SIXE Partner

+34 91 198 02 43 (EU)

+1 628 90 03 024 (US)

Mon – Fri | 8:30 – 16:30 (GMT + 1)

“Diversity is about being invited to the party. Inclusion is to be asked to dance”, Verna Myers. At SIXE we work to make both happen, 100% remotely.

Partners

  • Canonical
  • Docker
  • HCL
  • IBM
  • Kaspersky
  • Lenovo
  • Red Hat
  • Sealpath
  • SUSE
  • Tenable

Our mission

SIXE ensures that your infrastructures based on IBM®, Red Hat®, Canonical®, and SUSE® technologies remain stable, secure, and optimized for as long as you need them.

At SIXE, we are committed to sustainability. That’s why we help you design, implement, and maintain durable and efficient technological solutions.

SIXE green energy

© 2026 - SIXE | Training, consulting, professional services and turnkey projects | IBM, Lenovo, Canonical, Red Hat , HCL, Sealpath & SUSE Authorized Business Partner. | Become a SIXE Partner | Company registered in INCIBE's cyber security catalog. |
HQ - Madrid | Barcelona | Paris | Bruxelles
  • Link to LinkedIn Link to LinkedIn Link to LinkedIn
  • Link to X Link to X Link to X
  • Link to Facebook Link to Facebook Link to Facebook
  • cookie policy
  • Legal notice
  • Privacy Policy
Link to: IBM Z: Technical Overview of HW and SW Mainframe Evolution Link to: IBM Z: Technical Overview of HW and SW Mainframe Evolution IBM Z: Technical Overview of HW and SW Mainframe EvolutionLink to: Advanced z OS Performance: WLM, Sysplex, UNIX Services, z Systems Link to: Advanced z OS Performance: WLM, Sysplex, UNIX Services, z Systems Advanced z OS Performance: WLM, Sysplex, UNIX Services, z Systems
Scroll to top Scroll to top Scroll to top
SIXE
SIXE
Manage cookie consent

At SIXE, we prioritize your comfort and security. These technologies help us optimize our services, personalize content and offer you solutions tailored to what you really need. Your privacy is important: you will always be in control of what you share with us.

Funcional Always active
El almacenamiento o acceso técnico es estrictamente necesario para el propósito legítimo de permitir el uso de un servicio específico explícitamente solicitado por el abonado o usuario, o con el único propósito de llevar a cabo la transmisión de una comunicación a través de una red de comunicaciones electrónicas.
Preferences
El almacenamiento o acceso técnico es necesario para la finalidad legítima de almacenar preferencias no solicitadas por el abonado o usuario.
Statistics
El almacenamiento o acceso técnico que es utilizado exclusivamente con fines estadísticos. El almacenamiento o acceso técnico que se utiliza exclusivamente con fines estadísticos anónimos. Sin un requerimiento, el cumplimiento voluntario por parte de tu Proveedor de servicios de Internet, o los registros adicionales de un tercero, la información almacenada o recuperada sólo para este propósito no se puede utilizar para identificarte.
Marketing
El almacenamiento o acceso técnico es necesario para crear perfiles de usuario para enviar publicidad, o para rastrear al usuario en una web o en varias web con fines de marketing similares.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
See preferences
  • {title}
  • {title}
  • {title}