Safeguard Reference Manual (G06.29+, H06.08+, J06.03+)

Table Of Contents
Introduction
Safeguard Reference Manual 520618-030
1 - 7
File-Sharing Groups
°
Auditing specifications
The owner of an OBJECTTYPE authorization record can modify the record
(ALTER OBJECTTYPE).
The owner of an OBJECTTYPE record can freeze and thaw access to the
OBJECTTYPE (FREEZE OBJECTTYPE and THAW OBJECTTYPE).
The owner of an OBJECTTYPE record can delete the record (DELETE
OBJECTTYPE).
File-Sharing Groups
The Safeguard software allows you to create user groups for file-sharing purposes.
With the GROUP commands, users can be assigned to multiple groups and group
membership can be extended beyond 256 users. Section 7, Group Commands,
describes how to create and maintain file-sharing groups.
Security Groups
The Safeguard software allows you to create the following security groups to restrict
the use of SAFECOM commands: SECURITY-ADMINISTRATOR, SYSTEM-
OPERATOR, SECURITY-OSS-ADMINISTRATOR, SECURITY-PRV-
ADMINISTRATOR, SECURITY-AUDITOR, SECURITY-MEDIA-ADMIN, and
SECURITY-PERSISTENCE-ADMIN. After the security groups are created, only the
group members can execute certain TERMINAL, EVENT-EXIT-PROCESS,
SAFEGUARD, and audit service commands. Security group membership also
determines who can alter the Safeguard configuration and stop the Safeguard
software. For more information on how to create and maintain the security groups, see
Section 13, Security Group Commands.
Terminal Control
The TERMINAL commands allow you to define terminals on your system so that the
Safeguard software controls those terminals. When the Safeguard software controls a
Note. Starting with H06.24/J06.13 RVUs, the OBJECTTYPE USER is granted additional
access permissions, WRITE (W) and PURGE (P), along with the existing CREATE (C) and
OWNER (O) permissions. Members having the WRITE (W) permission on OBJECTTYPE
USER can modify any subject records. Members having the PURGE (P) permission on
OBJECTTYPE USER can purge any subject records.
Note. Starting with H06.26/J06.15 RVUs, the OBJECTTYPE
DISKFILE/VOLUME/SUBVOLUME is gra
nted additional access permissions, WRITE (W)
and PURGE (P), along with the existing CREATE (C) and OWNER (O) permissions.
Members having the WRITE (W) permission on OBJECTTYPE
DISKFILE/VOLUME/SUBVOLUME can modify the respective
DISKFILE/VOLUME/SUBVOLUME protection records. Members having the PURGE (P)
permission on OBJECTTYPE DISKFILE/VOLUME/SUBVOLUME can purge the respective
DISKFILE/VOLUME/SUBVOLUME protection records.