Skip to main Content

Pervasive Encryption on zOS

  • Référence ESS10G
  • Durée 3 jour(s)

Classe inter en présentiel Prix

EUR2,550.00

hors TVA

Demander une formation en intra-entreprise S'inscrire

Modalité pédagogique

La formation est disponible dans les formats suivants:

  • Classe inter à distance

    Depuis n'importe quelle salle équipée d'une connexion internet, rejoignez la classe de formation délivrée en inter-entreprises.

  • Classe inter en présentiel

    Formation délivrée en inter-entreprises. Cette méthode d'apprentissage permet l'interactivité entre le formateur et les participants en classe.

Demander cette formation dans un format différent

In this course you will learn how to implement Pervasive Encryption in your z/OS installation. The course explores in detail, the various technologies that are involved in z System and z/OS Cryptographic Services, ICSF, RACF and DFSMS access method Services.

In the hands-on exercises, you begin with the setup of your hardware crypto environment (CCA crypto express and CPACF), then you will load and activate your AES master keys, setup ICSF and its Key datasets (CKDS PKDS TKDS), then define your data encryption keys, activate your data set encryption policy, and encrypt your data sets and zFS filesystems.

These exercises reinforce the concepts and technologies being covered in the lectures. This course consists of several inter-dependent modules. The modules, including the lab exercises, depend on the other previous modules content.

Prochaines dates

Haut de page

This class is intended for z/OS system programmers and security specialists in charge of designing, implementing and monitoring Pervasive Encryption on z/OS.

Objectifs de la formation

Haut de page

In this course, you will learn how to:

  • Describe the components of Pervasive Encryption on z/OS
  • Explain the role of encryption for data protection
  • Implement hardware crypto on your z System
  • Load and activate AES Master Keys
  • Implement and start ICSF
  • Understand the differences between secure keys clear keys and protected keys
  • Describe how are key values used for encryption and decryption
  • Generate, maintain and manage Keys
  • Setup access to key labels
  • Setup policy to supply key label (RACF SMS JCL)
  • Access data in encrypted data sets
  • Create encrypted data sets - Supplying key labels
  • Convert existing data sets to encryption
  • Verify encryption status
  • Encrypt Data in Transit
  • Encrypt Data at Rest
  • Manage data sets, data keys, and key labels

Programme détaillé

Haut de page

 Day 1

  • Welcome
  • Unit 1: Pervasive Encryption Technical Foundation
  • Unit 2: Pervasive Encryption: Planning
  • Unit 3: Pervasive Encryption: implementation considerations
  • Unit 4: Dataset Encryption Implementation steps

Day 2

  • Exercise 1: Setup and start ICSF
  • Exercise 2: Load and initialize your AES master key and CKDS
  • Unit 5: ICSF and crypto on z/OS
  • Exercise 3: Define your data keys
  • Exercise 4: Implement dataset encryption policy, encrypt/decrypt data sets

Day 3

  • Exercise 5: Operational tasks for managing data sets, data keys, and key labels
  • Unit 6: Key management: ICSF and the Crypto Ecosystem on Z
  • Unit 7: z15 Hardware Encryption Overview and Performance
  • Exercise 6: Master Key Change using ICSF (optional)
  • Exercise 7: Implement zFS encryption (optional)

Pré-requis

Haut de page

You should have the following prerequisites:

  • General z/OS knowledge, including basic UNIX System Services skills
  • Basic knowledge of RACF

Certification

Haut de page
None

Et après 

Haut de page
None

Bon à savoir

Haut de page
  • Official course book provided to participants.