Configure z/OS Management Facility for CA Top Secret

IBM® z/OS® Management Facility (z/OSMF) provides system management functions in a task-oriented web browser-based user interface with integrated user assistance, so that you can manage the day-to-day operations and administration of your z/OS systems. By streamlining some traditional tasks and automating others, z/OSMF can help to simplify some areas of z/OS system management.
ctsfz
IBM® z/OS® Management Facility (z/OSMF) provides system management functions in a task-oriented web browser-based user interface with integrated user assistance, so that you can manage the day-to-day operations and administration of your z/OS systems. By streamlining some traditional tasks and automating others, z/OSMF can help to simplify some areas of z/OS system management.
z/OSMF includes the following components:
  • z/OSMF nucleus
  • Core (recommended) services, such as administration, workflow, and notification tasks
  • Optional services, such as the ISPF, Sysplex Management, and Capacity Provisioning services
To configure z/OSMF for CA Top Secret, you first prepare the CA Top Secret environment and define authorizations for the z/OSMF nucleus and core services. You then define authorizations for the optional services as needed for your site's z/OSMF implementation. The services that you add depends on your site's goals.
The following graphic provides a high-level overview of the configuration process for z/OSMF:
z/OSMF Configuration Overview
A high-level overview of the configuration process for z/OSMF.
Some services jobs (for example, TSSWMSEC and TSSCPSEC) create profiles and groups for providing authorizations to users. To help you connect users to the roles and groups that you created when executing the other jobs, CA Top Secret provides the TSSAUTH job. For TSSAUTH to work successfully, those profiles and groups
must
already exist. Therefore, run the TSSAUTH job last.
The following table lists the z/OSMF security jobs for CA Top Secret.  These jobs reside in the
your_hlq
.CAKOJCL0 data set.
z/OSMF Area To Be Configured
Description
Security Job Name in
your_hlq
.CAKOJCL0
Nucleus
Nucleus
TSSNUSEC
Notifications task
Core service
Part of TSSSEC
z/OS data set and file REST services
Core service
Part of TSSSEC
z/OS jobs REST services
Core service
Part of TSSSEC
Swagger service
Core service
Part of TSSSEC
TSO/E address space services
Core service
Part of TSSSEC
z/OSMF administrative tasks
Core service
Part of TSSSEC
z/OSMF settings service
Core service
Part of TSSSEC
z/OSMF Workflows task
Core service
Part of TSSSEC
All of the above
Nucleus, plus all core services
TSSSEC
Capacity Provisioning service
Optional service
TSSCPSEC
Cloud Provisioning services
Optional service
TSSPRSEC
Console services
Optional service
TSSGCSEC
Incident Log service
Optional service
TSSILSEC
ISPF service
Optional service
TSSISSEC
Network Configuration Assistant service
Optional service
TSSCASEC
Resource Monitoring service
Optional service
TSSRMSEC
Security Configuration Assistant
Optional service
TSSSASEC
Software Management service
Optional service
TSSDMSEC
Sysplex Management service
Optional service
TSSSPSEC
Workload Management service
Optional service
TSSWMSEC
z/OS Encryption Readiness Technology (zERT) Network Analyzer
Optional service
TSSNASEC
Common Event Adapter (CEA)
Additional security configurations
TSCEASEC
Common Information Model (CIM) server
Additional security configurations
TSCFZSEC
Capacity Provisioning Task edit or view functions
Additional security configurations
TSCP1SEC
Provisioning Manager Security related functions
Additional security configurations
TSCP2SEC