Skip to content
Open access

Privileged Access Management for z/OS System Programmers: A Zero-Trust Control Framework for RACF, TSO, and SDSF Administrative Sessions

Jul 2026 · Journal of Intelligent Decision Making and Information Science · Vol 3, pp. 1559-1582 · 0 citations · 25 references

TL;DR

A new control approach for PAM known as the Zero-Trust Control Framework, based on behavioural analysis, graph theory, and entropy calculations is proposed, based on behavioural analysis, graph theory, and entropy calculations for enhancing zero trust enforcement in z/OS administration.

Abstract

The PAM in z/OS systems needs additional measures in the realm of protecting sensitive data from misuse by insiders and credential abuse. Classic approaches using authentication through static mechanisms do not provide adequate protection of administrative sessions that use RACF, TSO, and SDSF, thus leaving systems open to risks associated with administrative activities. To combat these risks, this paper proposes implementing a new control approach for PAM known as the Zero-Trust Control Framework, based on behavioural analysis, graph theory, and entropy calculations. The new tool developed as part of this framework is called Behavioural Identity Drift Analyzer (BIDA). As such, the Privilege Interaction Graph Transformer (PIGT) leverages graph neural networks and transformers to generate privilege interaction graphs that detect the escalation routes, dependencies, and propagation vectors of insider threats in near real-time. Lastly, the Entropy Adaptive Zero-Trust Orchestrator (EAZTO) analyzes uncertainties in user actions, commands, and privileges in order to apply adaptive control measures such as multi-factor authentication, privilege reduction, or even session termination. In combination, these four modules provide layers of protection and achieve continuous PAM decision-making at 90 percent accuracy for the purpose of enhancing zero trust enforcement in z/OS administration.

Read PDF

Similar papers

#data science Open access Oct 2026

Zero Trust for SQL Server: A Three-Layer Security Architecture

This study designed and empirically validated a three-layer Zero Trust architecture for Microsoft SQL Server that natively integrates instance-level authentication governance, enhanced Role-Based Access Control with Row-Level Security and Just-in-Time privilege elevation, and metadata-driven Attribute-Based Access Cont...

Maynard Capil, D. Dasig · 0 citations

Named, Secured Data as a Foundation for Zero Trust A Conceptual Comparison of Today’s Zero Trust Realizations and NDN Security Architecture

This architecture provides a systematic foundation for the three core Zero Trust behaviors while eliminating, for participating mechanisms that use the coordinated namespace, the class of cross-namespace correspondence dependencies the authors call identifier glue.

Li-Xia Zhang · 0 citations
Case report 2026

From HAL to SMC : a normal-world view of ARM TrustZone on Android

The findings show that kernel-level data-transport and synchronization choices directly influence the classes of concurrency and memory-sharing defects exposed by each TEE architecture.

David Ada · 0 citations
Preprint Aug 2026

Building the Truman Show: A TrustZone-Based Framework for Lightweight Out-of-band Kernel Security Monitoring

The increasing number of vulnerabilities in operating systems, together with sophisticated kernel-level threats (e.g., rootkits), has weakened the effectiveness of traditional in-kernel protection mechanisms. Since these defenses operate at the same privilege level as the kernel, they share the same attack surface and...

Zhen-Ling Duan, Pan Dong, Renshuang Jiang et al. · 0 citations
#artificial intelligence Review Sep 2026

Zero-Trust Authorization and Discovery for Enterprise MCP

LLM agents translate natural-language context, which may include attacker-controlled text, into privileged tool calls, so authorization must remain effective even when an agent is prompt-injected or adversarially steered. The Model Context Protocol (MCP) has become a widely adopted interface for this boundary, yet its...

Huang-Jian Li, Yu-Wei Wang, Srinivasan Manoharan · 1 citation
Open access Sep 2026

An Author’s Taxonomy of Customer-Observable Security Controls in SaaS Platforms

The software-as-a-service model places most technical security mechanisms in the provider's hands, while the customer remains accountable for data, identities, and regulatory outcomes. Certification reports describe what a provider has implemented, yet reveal little about what a tenant can monitor and verify on its own...

Sergei Beliachkov · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.