![]() ![]() |
|||||||||||||||||
|
Overview Administering an application in a complex computing environment, such as at U.C., Santa Barbara, can be daunting for a new administrator. This document is intended to present important information that new and experienced administrators may find useful in their work. To begin with, an administrator should have an understanding of Com-Plete Userids and the elements of good password design, to help you and your staff better secure access to University data. It's imperative that administrators know their departmental application in order to better administrate it. You need to be the expert on any "front-end" security (should it exist) for your application or system. You should have a basic understanding of the authorization process because you may be requesting access to other applications, or, deciding on access requests for the application you administer. If you are an application "owner", you may receive various security reports to help you manage your application. You need to know how to read and interpret these reports. Finally, an understanding of procedures will help you interface with IS&C security administration.
Topics: Who
is This Guide For? How to Close Access How to Change a User Profile How to Have a Password Reset Everything You Ever Wanted to Know About a Com-Plete Userid How to Become Expert on Your Application or System Password Design Elements Reporting a Security Breach Security Reports System Monitoring Information Just For the All-In-One DSA Com-Pass Screen or All-in-One Menu Chart of Account Department Codes E-mail Nicknames
This Department Administrator Guide is intended to assist campus administrators, located in administrative or academic departments, who are responsible for OS/390, Com-Plete, Natural, or PL/1 applications, running on IS&C's Enterprise Server, located in North Hall. If you are . . .
. . . then this Department Administrator Guide is intended for you. The information contained within this Guide is not considered "sensitive" and is intended for public dissemination.
The Authorization Process - How it Works For Com-Plete Userid billing. All Com-Plete Userids are billed to a Computer Center account. A request to set up a new Com-Plete Userid may require the IS&C Accounts Administrator to contact your department's account controller to authorize the creation of a new account and approve any allocation of funds to that account. A Com-Plete Userid cannot be activated unless a funded Computer Center account exists. For linking a Com-Plete Userid to a Production Application. Each application running under Com-Plete has a registered owner known as a "Department of Record". For each department application there is at least one department administrator responsible for authorizing access requests from prospective users. Once formal authorization is received (normally by E-mail), IS&C security administration will proceed with the request. Access requests and department authorizations are filed for audit purposes (there are several access request forms available on the web, including the "Com-Plete Request" form and the "All-in-One Request" form). IS&C security cannot process an access request until approval has been received from the department of record. For a Test Application. Each "TEST" application running under Com-Plete is administered either by the IS&C Financial Systems Manager or the IS&C Student Systems Manager. Normally, access to a TEST application is restricted to a developer. A developer may request access to a TEST application by contacting the appropriate IS&C Manager. If approved, the IS&C Manager will notify IS&C security administration to set up access. For Adabas and Natural File Access. A request to link a Natural or Adabas file to an application or system is normally authorized by the department that is billed for the file. For access to a OS/390 Partitioned Data Set. A "Partitioned Data Set", or PDS, is a special type of library that may contain, for example, JCL, Natural code, or data. Many of these libraries have a registered departmental owner and are secured by RACF. If you are a department administrator responsible for one or more OS/390 Partitioned Data Sets, IS&C security administration will be in contact whenever an access request is received. Once formal authorization is received (normally by E-mail), IS&C security administration will proceed with the request. Access requests and department authorizations are filed for audit purposes. IS&C security cannot process an access request until approval has been received from the department administrator. As a department administrator, you should to be familiar with some of the most common IS&C security procedures. To open a Com-Plete Userid requires that an applicant submit a request form. The request form to be used differs somewhat from application to application. To determine which application form to use, you need to be able to answer these questions:
Once you have the answers to the above questions, the general application process is as follows:
Deletion of a Com-Plete Userid is normally a two step process: the Userid is deleted from Com-Plete and the Computer Center account is closed (Note: a Computer Center account should remain open if other Computer Center services (such as email) are to remain in use; in such instances only the Com-Plete Userid is deleted). As a Userid is normally assigned to an individual, a department administrator should try to anticipate personnel changes (if possible) and arrange to set up a new, replacement, Userid to minimize disruption of work. A Userid can be deleted and/or an account closed for any of the following reasons:
How to Change a User Profile When a Com-Plete Userid is initially set up, a User Profile consisting of Account, User Name, Output Bin and Destination is created. The User Profile has many uses, including:
Current settings for a User Profile are displayed on any Job Submission screen. The user profile may be need to be changed if there has been:
Send an Email note to isc.security@isc.ucsb.edu to request changes to a User Profile. On this note detail any user profile change you wish to make.
IS&C security distinguishes among types of administrators based on function. These 3 types include:
In practice, a large number of departments have chosen to combine these 3 functional types into one individual, who is often the accounts administrator (these departments have chosen a "1 tier" approach, the least complex). Many such departments do not own applications themselves, but apply to other departments that do. Some departments combine the functions of an application owner and day-to-day administrator into one individual, but separate those duties from a departmental accounts administrator (these departments have chosen a "2 tier" approach). These departments have decided that a certain amount of specialization is required to manage budgets as opposed to administering a department system (such as the Accounting owned APEX system). A small number of departments have delegated these 3 functional types among different employees (these departments have chosen a "3 tier" approach, the most complex). In part splitting the "ownership" function from the "day-to-day" administrative functions is necessitated by the workload required for maintenance (such as for the Registrar owned STAR01 system). However these functions are assigned, care must be exercised to avoid miscommunication within a department, or, between a department and IS&C, or between departments. As an department administrator you should know how your particular department distributes (or combines) these functions within the department.
Each Natural application has one or more registered owners (entered in Predict). Specifically, an application owner is responsible for: If you need to know who is the registered application owner for a particular application, contact IS&C security administration. Usually, the day-to-day administrator is responsible for: - add a user record - change a user record - review a user record - purge or delete a user record - run reports - configure the screens a user may (or may not) view If you need to know who is the day-to-day administrator for a particular application, contact IS&C security administration. Usually this involves: If you need to know who is the accounts administrator for a particular department, contact the IS&C Accounts Administrator. A Userid is a unique identifier that enables a user to logon to Com-Plete, thereby accessing various computing services for which the user has been authorized. Spelling. The term "userid" has several valid spellings, which you may encounter, including, for example, User ID, USERID, Userid, and User-ID. Purpose. A Userid is a simple way to authenticate a user to Com-Plete. Role of IS&C security administration. IS&C security administration is responsible for setting up a Com-Plete Userid. In order to maintain an audit trail, all Com-Plete Userids are kept for a minimum of 7 years after an employee separates or terminates. Userid Types: Personal. A "personal" Userid is the most popular kind of Userid assigned. It is assigned to one particular individual for their exclusive use. This type of Userid has the following restrictions.
Shadow. A user may have more than one Userid, if their work requires it. Each additional personal Userid is known as a "shadow" Userid. This type of Userid has the following restrictions:
Generic. Several individuals may use a "generic" Userid assigned to a departmental position. Most positions that utilize temporary or casual employees benefit from this type of Userid. This type of Userid is subject to some restrictions.
How to Become Expert on Your Application or System Did you know that there are almost 150 administrative applications currently in use, with new ones under development! If you are an application administrator you are empowered to make decisions regarding access requests and permissions. IS&C security is here to assist you in administering your application, but you must know your application. Here are some ways to learn more about your application or system:
Four elements of a "Job Submission" screen are set up by IS&C security administration when a user is added to Com-Plete, including: Taken together, these four elements are known as a User Profile. As an administrator you can coordinate modifications to a User Profile for a user in your department (such as changing the printer Destination). See the section named Change User Profile for more information on how to submit such requests. The remaining items on a "Job Submission" screen (such as CPU Time, Print Lines, Message Class, Copies, and Forms) are programmatically controlled by the application itself and are not maintained by IS&C security administration. Detailed information regarding all the elements of the "Job Submission" screen and Job Control Language (JCL) is available in this document on JCL.
Application administrators are responsible for approving the setting up (or closing down) of Com-Plete Userids, for authorizing access to an application, for application security and receive IS&C Security reports. Such administrators usually know a great deal about the data, files and security structure of an application. In many departments, the functions of the account administrator and application administrator are highly specialized with one user focusing on accounts, and another user focusing exclusively on application administration. In other departments, these functions are combined and a single user acts as both the account and application administrator. As a department adminzistrator you should know whether these functions are specialized, or, combined. If these functions are specialized, coordination in your department is required between the accounts administrator and application administrator to ensure that a Computer Center account is not closed for an active Com-Plete Userid. Generally, application-level security allows a department administrator to: IS&C security administration is not empowered to maintain any "application-level" security. Consequently, IS&C security administration can only provide minimal assistance should any questions or problems arise with "application-level" security. If you need further information, contact IS&C security administration for a quick orientation. A Password is a string of alpha-numeric characters used in conjunction with a Userid to logon to Com-Plete. A password is used to verify that an individual is the legitimate user of a Userid. User Responsibilities
Responsibilities of a Department Administrator
Responsibility of IS&C Security Administration
The following tables summarize the enforced and recommended password design elements of Com-Plete.
Contact your Manager, IS&C Security Administration, or Internal Audit to report it. As an administrator you may receive from IS&C security administration several different security reports to assist you in administering an application. In addition, there is a security report you may generate yourself at your convenience. (1) Department "Security Report" If you are a registered application owner, you will receive a Department "Security Report" for each application you administer (your name appears as an "APPLICATION AUDITOR"). The purpose of the "Security Report" is to show who has access to the application that you administer. Users can be linked to your application as an individual, or as a member of a group of users. This report is generated by IS&C security and is distributed quarterly. Enclosed with each report is a cover letter that highlights the elements of the report. Should you need clarification regarding any portion of the report, contact IS&C security administration. Displayed below is an abridged sample of a fictitious "Security Report" for an application named LIMA01.
(2) "Current Employees with Com-Plete Access" Report A department receives the "Current Employees with Com-Plete Access" report if the department has at least one individual with an existing Userid. The purpose of this report is to list all users in your department that have access to Com-Plete. This report is intended to help you (1) administer your department's access to university data, and (2) administer your department's computing expenses. This report is generated by IS&C security administration twice a year. Enclosed with each report is a cover letter that highlights the elements of the report. For each employee the report prints Name, Userid, Phone, department code and Job Title. There are 4 check-boxes:
Should you need clarification regarding any portion of the report, contact IS&C security administration.
(3) "List of Datasets Billed" Report This report displays all OS/390 and Adabas data sets being charged to a specified account. This report is a valuable tool that will help you track certain computing expenses. As a department administrator, you may run this report at any time. To run this report: Logon to the Natural application named UTILITY. This is a special library containing public utilities for Com-Plete and Natural users. On the Main Menu, find the function named Submit 'Billed Datasets' Report. Input the code for that function; press Enter. A "Job Submission" screen will be displayed (named "Submit List of Datasets Billed"). Your screen should resemble the below example. Follow the instructions as indicated on this screen (press PF4 to submit). The report will be printed at the "Destination" displayed.
The printed report generated by you will resemble the following example (note, your report may differ greatly, depending on the number of data sets you have).
Selected requests for security reports will be honored by IS&C security administration on an case-by-case basis, such as:
If you might be interested in a special report, contact IS&C security administration. System MonitoringMonitoring of the OS/390, Com-Plete and Natural computing environments is a normal function of IS&C security administration. Information Just for the All-in-One DSA As a DSA, you can list security group assignments for your department on-line. There are 2 ways to generate this list:
By use of menu functions:
If you are a DSA responsible for multiple departments, type additional department codes in the Dept Code field on the "Browse Security Group Members" screen to view security group assignments for other department codes. Com-Pass Screen or All-in-One Application MenuThe Com-Pass screen and the Application Menu are the two methods currently available for accessing Com-Plete. Technically known as a "user-interface" each differs widely in its appearance and functionality. If you are a Department Security Administrator (DSA) you may need to decide which user-interface is appropriate for an applicant. * The Com-Pass
screen is the default user-interface to Com-Plete (view
sample) * The Application Menu
is a featured user-interface available for users of the All-In-One
Financial System (view
sample) When an All-In-One request form is received:
Exceptions. An All-In-One user will not be converted to, or, set up with the Application Menu if:
The "Chart of Account" department codes are administered by the General Accounting section in Accounting and Financial Services . These department codes are 4 characters in length. All departments at U.C.S.B. have at least one "Chart of Account" code. Role of All-In-One Department Security Administrator (DSA).
Role of IS&C Security Administration.
Role of Accounting and Financial Services.
All users of the All-In-One Financial System are required to have a current, valid, E-mail address and a corresponding E-mail nickname. As a DSA, it is your responsibility to:
|
|||||||||||||||||
|
For assistance or further information please contact webcontact@ucsbuxa.ucsb.edu . Last Modified: CGH,01/30/02 |