Feedback

IBM Tivoli zSecure suite V1.11 extends compliance and audit management capabilities while helping simplify and extend administration, auditing, monitoring, and compliance management of System z security

IBM United States Software Announcement 209-385
November 3, 2009

 
 ENUS209-385.PDF (167KB)

Table of contents   Document options  
Overview Overview Publications Publications
Key prerequisites Key prerequisites Technical information Technical information
Planned availability date Planned availability date Ordering information Ordering information
Description Description Terms and conditions Terms and conditions
Product positioning Product positioning Prices Prices
Program number Program number Order
now Order now
 
Printable version Printable version

 
Top rule
At a glance
Bottom rule

Tivoli® zSecure suite V1.11 can help you enhance the security of mainframe systems by:

  • Automating routine administrative tasks to help reduce costs and improve productivity
  • Monitoring and auditing incidents to help detect and prevent security exposures
  • Supporting an enterprise-wide view of audit and compliance efforts, helping increase the integrity of mainframe security
  • Providing monitoring, auditing and reporting of z/OS®, RACF®, CA ACF2, and CA Top Secret, UNIX®, CICS®, and DB2®
  • Offering a wide variety of canned audit reports and the capability to create specialized reports
  • Allowing you to capture and show more comprehensive historical reporting
  • Providing auditing assistance related to Federal Information Seurity Management (FISMA), Payment Card Industry (PCI), Sarbanes-Oxley Act (SOX), and Japanese Sarbanes-Oxley Act (JSOX).
  • Helping increase the integrity of RACF mainframe security
  • Offering extended and independent monitoring to track and assess the consistency of security relevant changes to z/OS across systems and the compliance of those changes in comparison to a best practice knowledge base
  • Extending monitoring and alerting for security events from IBM® Tivoli Key Lifecycle Manager, OMEGAMON®, RMM and IBM WebSphere® Application Server V7

For ordering, contact: Your IBM representative or an IBM Business Partner. For more information, contact the Americas Call Centers at 800-IBM-CALL (426-2255).

Reference: LE001


 
Back to topBack to top
 
Top rule
Overview
Bottom rule

Tivoli zSecure suite V1.11 for z/OS consists of multiple individual components designed to help you administer your mainframe security server, monitor for threats, assist in compliance monitoring and auditing, audit usage and configurations, and enforcing policy compliance.

Tivoli zSecure Admin, Visual and CICS Toolkit provide administrative, provisioning, and management components that can significantly reduce administration time, effort, and costs by contributing to improved productivity, faster response time, and reduced training time needed for new administrators and implementation of decentralized administration.

Tivoli zSecure Audit, Alert, and Command Verifier provides audit, monitoring and compliance management components. These offerings help ease the burden of compliance audits, can improve security and incident handling, and can increase overall operational effectiveness. Offerings include:

Tivoli zSecure suite V1.11 enhancements:

  • Currency with z/OS V1.11:
    • Format and analyze live Communication Server (TCP/IP) stack configuration information for auditing and alerting
    • Support for new RACF and SMF fields for identity propagation
    • Support Load Module Signature Verification regulation requirements
  • Ability to address the problem of obsolete authorizations with RACF database clean-up function (including unused user, group authorizations, and unused connects)
  • Ability to report on additional z/OS UNIX system management facility (SMF) events
  • Integration with CICS to deal with multiple events contained in a single CICS SMF 110 Record, plus new CICS event information provided to Tivoli Compliance Insight Manager
  • Ability to report on IBM Data Facility Storage Management Subsystem (DFSMS™) Removable Media Manager (RMM) new dynamic variants
  • Extended monitoring of status changes in z/OS and RACF
  • Using MVS™ System Management Facilities (SMF) format administrative commands from OMEGAMON for regulatory compliance
  • Ability to integrate with OMEGAMON for reporting commands
  • Support Partitioned Data Set Extended (PDSE) member level auditing
  • Audit and Alert on Internet Protocol Security (IPSEC) configuration information
  • Ability to integrate with IBM Tivoli Key Lifecycle Manager for security events
  • Report on IBM WebSphere Application Server V7 security events
  • Audit and report for security events from Object Access Method (OAM) by using SMF
  • Administration enhancements to the user interface (UI) for multiple permits and connects
  • Multiple administration enhancements to ease and simplify reporting and administration tasks
  • Ability to exploit new functionality for CA ACF2
  • Ability to deliver globalization enhancements for Double Byte Character Set (DBCS)

Additional offerings include:

  • IBM Tivoli Compliance Insight Manager Enabler for z/OS
  • IBM Tivoli zSecure Manager for RACF z/VM® V1.8.1

 
Back to topBack to top
 
Top rule
Key prerequisites
Bottom rule

For details, refer to the Hardware requirements and Software requirements sections.


 
Back to topBack to top
 
Top rule
Planned availability date
Bottom rule

November 6, 2009


 
Back to topBack to top
 
Top rule
Description
Bottom rule

The zSecure family of products provides a user-friendly interface for RACF, with extensive auditing and monitoring capabilities for the enterprise security hub, which can result in more efficient and effective administration and compliance to defined security policies.

Helps free administrators to focus on security

While preventing security breaches is paramount, administrators are frequently bogged down with tedious, time-consuming day-to-day tasks that divert their attention from security issues. The Tivoli zSecure suite offers a range of products designed to help reduce administration time, and enable valuable mainframe resources to focus on improving security quality.

Tivoli zSecure Admin is a leading security software program that enables efficient and effective IBM RACF administration, typically using significantly less resources. By putting a user-friendly layer over your RACF databases, you can quickly enter and process administrative commands, generate custom reports, and clean up databases. By implementing a repeatable process for security management, Tivoli zSecure Admin can help you reduce errors and improve the overall quality of services.

RACF administrators can create a mirrored offline copy of the RACF database that can be used to check and verify configuration changes, without affecting the production database. This ability to test changes and review the results before implementing them can reduce the risks of introducing errors into the production database, through human error, and possible outages of security.

RACF database clean-up function addresses the problem of obsolete authorizations, which is an administrative issue that is increasingly unacceptable from a compliance, governance, and risk perspective. For example, by removing authorizations that have not been used for a year. This pertains to unused permits (user and group authorizations) as well as unused connects (group membership). At the same time, if the authorizations are obsolete, it is likely that the corresponding resources are equally obsolete and should also be cleaned up. Obsolete resources on the system represent a security risk because they could be reused for another purpose, and inappropriate access might be granted by virtue of the obsolete authorizations lingering in the security database.

Removal of unused profiles is also possible but requires a manual review step since there exists reasons for the existence for a profile that the program cannot know. The RACF Cleanup function can be used to reduce the overhead of the processing around yearly authorization reviews demanded by some regulations.

Tivoli zSecure Visual can reduce the need for expensive, RACF-trained expertise through a Microsoft® Windows-based GUI for RACF administration. With the ability to establish a secure connection directly with RACF, Tivoli zSecure Visual is ideal for decentralizing RACF administration or enabling central security administration from outside Interactive System Productivity Facility/Time Sharing Option (ISPF/TSO).

Track security events and help prevent exposures to compliance requirements

Over the past decade, the number of requirements organizations must comply with has increased dramatically. Keeping up with the demands for audit and controls documentation, while also trying to prevent security breaches, can be overwhelming. The Tivoli zSecure suite delivers auditing, monitoring, and compliance management solutions designed to help reduce security exposures.

Tivoli zSecure CICS Toolkit, a component of the IBM Tivoli zSecure suite, adds mainframe administration capabilities to the CICS environment, such as password resets and authorization management. The easy-to-use Tivoli zSecure CICS Toolkit menu enables users to stay within the CICS application, rather than forcing them into another environment, to issue security commands to the mainframe. Your field administrators will quickly be able to issue commands through a user-friendly menu for functions like password resets for failed user logins and user additions.

If you have an application on your Web server that communicates with CICS on your mainframe, your CICS application can use the advanced COBOL API capabilities in Tivoli zSecure CICS Toolkit to execute select RACF security functions. Such functions could be verification of a user ID and password entered on the Web interface against the RACF database or retrieval of information about a user ID and its privileges from the RACF database that gets passed on to the Web application. You can easily customize Tivoli zSecure CICS Toolkit screens by using the API, which can be contacted by any CICS program with a standard CICS command area. Use the API to tailor the look of your screens to the requirements of a specific installation and show as little or as much as you want to your decentralized administrators. The API facilitates access checks of more than 2,000 resources, enabling you to easily replace an application's internal security with RACF security and helping to significantly improve the application's performance. Tivoli zSecure CICS Toolkit API can centralize - in the RACF database - the security of (homegrown) applications built for CICS.

Tivoli zSecure Audit delivers a mainframe compliance management and audit solution that enables you to quickly analyze and report on mainframe events, and automatically detect security exposures through extensive status auditing. zSecure provides extended and independent monitoring to track and assess the consistency of security relevant changes to z/OS across systems and the compliance of those changes in comparison to a best practice knowledge base. Extended monitoring and alerting of security events from IBM Tivoli Key Lifecycle Manager, OMEGAMON, RMM and IBM WebSphere Application Server V7 assist in providing an improved view of the over all security within the mainframe environment. The technology lets you create standard and customized reports, that can be generated in Extensible Markup Language (XML) format and used in databases and reporting tools.

Tivoli zSecure Audit also lets you send Simple Network Management Protocol (SNMP) messages to an enterprise management console for policy exceptions or violations that indicate a security breach or weakness. This capability is provided for RACF, CA Top Secret, and CA ACF2 environments.

Tivoli zSecure Alert offers a real-time mainframe threat monitoring solution that allows you to efficiently monitor intruders and identify misconfigurations that could hamper your compliance efforts. It goes beyond conventional intrusion detection solutions to support intrusion prevention by taking countermeasures via automatically generated commands.

In addition, Tivoli zSecure Alert enables you to quickly determine unauthorized logons and attempts, user behavior that violates security policy, and when your core systems are at risk. With this information readily in hand, you can help identify misconfigurations before they can be exploited, while staying one step ahead of the auditors. This capability is provided for RACF, and CA ACF2 environments.

Tivoli zSecure Command Verifier is a robust policy enforcement solution that can help enforce mainframe compliance to company policies by preventing erroneous commands. As a result, it helps increase control and decrease security risks and cleanup costs. Running in the background, Tivoli zSecure Command Verifier verifies RACF commands against your company's policies and procedures. When commands are entered, it verifies whether the commands comply with security policies--and blocks or, optionally, adjusts the ones that do not comply.

To address currency with the latest releases of z/OS and RACF, Tivoli zSecure suite V1.11 includes support for new RACF capabilities. Tivoli zSecure Admin, Audit, and Command Verifier support administration of, reporting on, and use of RACF commands and keywords. Tivoli zSecure is aware of new security relevant settings and new keywords to continue providing coverage for enhancements within z/OS and RACF, such as a new RACF class that was assigned for the health checker.

Tivoli Compliance Insight Manager Enabler for z/OS provides a link from zSecure Audit to the Tivoli Compliance Insight Manager tool, so that the mainframe audit information is included in the enterprise dashboard view.

Bringing it all together

The Tivoli zSecure suite is a valuable part of managing mainframe security as a process that helps meet the needs of auditors, and the business itself. These offerings are the result of a long-term commitment to innovation on the mainframe and to enabling you to improve and simplify mainframe security audit and administration. Through a broad range of offerings, the Tivoli zSecure suite helps you address your key mainframe challenges, such as:

  • Audit and compliance management
    • Report on questionable system configuration options and dangerous settings of privileged users.
    • Integrate with IBM Tivoli Key Lifecycle Manager, IBM WebSphere Application Server V7, and OMEGAMON for security event monitoring and reporting.
    • Measure and verify the effectiveness of mainframe security and security policies.
  • User and security administration
    • Include centralized and decentralized management and provision of users, profiles, and resources.
    • Constantly monitor crucial users and data for misuse.
  • Include security risk detection and avoidance:
    • Can reduce operational costs and achieve faster incident detection.
    • Generate alerts with instant reports about RACF, IBM System Management Facilities (SMF), IBM z/OS, IBM DB2, IBM CICS, and the UNIX subsystem.

Additional offerings include:

  • IBM Tivoli Compliance Insight Manager Enabler for z/OS

    Tivoli zSecure suite allows you to submit mainframe security information into an enterprise audit and compliance management solution, through the seamless integration with Tivoli Compliance Insight Manager. Combining mainframe data with that from other operating systems, applications, and databases, Tivoli Compliance Insight Manager provides the ability to capture log data, interpret that data through sophisticated log analysis and communicate results in an efficient, streamlined manner for full enterprise-wide audit and compliance reporting. Tivoli Compliance Insight Manager Enabler for z/OS provides the event source Connection to supply the mainframe information into the enterprise tool.

  • IBM Tivoli zSecure Manager for RACF z/VM V1.8.1

    Tivoli zSecure Manager for RACF z/VM provides administrators with tools to help unleash the potential of your mainframe system, enabling efficient and effective RACF administration, while helping use fewer resources. By automating many recurring system administration functions, Tivoli zSecure Manager for RACF z/VM can help you maximize IT resources, reduce errors, improve quality of services, and demonstrate compliance.

Accessibility by people with disabilities

A U.S. Section 508 Voluntary Product Accessibility Template (VPAT) containing details on accessibility compliance can be requested at

http://www.ibm.com/able/product_accessibility/index.html

Value Unit-based pricing

Value Unit pricing for eligible IBM System z® IBM International Program License Agreement (IPLA) programs enables a lower cost of incremental growth and enterprise aggregation. Each System z IPLA product with Value Unit pricing has a single price per Value Unit and a conversion matrix, called Value Unit Exhibit, for converting from some designated measurement to Value Units. Most commonly, Millions of Service Units (MSUs) is the measurement designated by IBM to be converted to Value Units. Some other measurements are engines or messages. Since MSUs are the most common measurement, that measurement will be used for the remainder of this description.

Value Unit pricing offers price benefits for you. For each System z IPLA program with Value Unit pricing, the quantity of that program needed to satisfy applicable IBM terms and conditions is referred to as the required license capacity. Each of the various Value Unit Exhibits stipulates that the larger your required license capacity, the fewer Value Units per MSU you will need. Value Unit Exhibits are uniquely identified by a three digit code and referred to using the nomenclature VUExxx, where xxx is the three digit code.

Subsequent acquisitions of Value Unit priced programs offer additional price benefits. The quantity of each System z IPLA program that you have acquired is referred to as entitled license capacity. If you wish to grow your entitled license capacity for a System z IPLA program, the calculation to determine additional needed Value Units is based upon the number of Value Units already acquired.

For each System z IPLA program with Value Unit pricing, you should:

  • Determine the required license capacity, in MSUs
  • Aggregate the MSUs across the enterprise
  • Convert the total MSUs to Value Units, using the applicable Value Unit Exhibit
  • Multiply the price per Value Unit by the total number of Value Units to determine the total cost

To simplify conversion from the designated measurement to Value Units or vice-versa, use the Value Unit Converter Tool. For additional information or to obtain a copy of the Value Unit Converter Tool, visit the Value Unit Converter Tool Web site

http://ibm.com/zseries/swprice/vuctool

Note that Value Units of a given product cannot be exchanged, interchanged, or aggregated with Value Units of another product.

To determine the required license capacity for the System z IPLA program you selected, refer to the Terms and conditions section.


 
Back to topBack to top
 
Top rule
Product positioning
Bottom rule

zSecure with Tivoli Compliance Insight Manager

Tivoli zSecure suite leverages the capabilities of Tivoli Compliance Insight Manager to enable inclusion of mainframe reporting on RACF, CA ACF2, and CA Top Secret into Tivoli Compliance Insight Manager enterprise-wide compliance dashboard and reporting, so that users can view the status of their enterprise security hub along with the rest of their environment. For more details refer to Software Announcement 207-149, dated July 3, 2007.

zSecure Alert with Tivoli Security Information and Event Manager

Tivoli Security Information and Event Manager and zSecure Alert are companion products that deliver a comprehensive view of the mainframe threats and incidents. Tivoli Security Information and Event Manager manages security operations effectively and efficiently with centralized security event correlation, prioritization, investigation and respose.

zSecure with RACF

Your investment in RACF may be enhanced with the addition of zSecure, which provides integrated security audit and compliance monitoring and administration for z/OS and RACF.

Mainframe auditing - For data center auditors, security managers, system programmers, and IT managers who need to monitor mainframe events and incidents, help reduce security vulnerability, and help enforce security policy compliance and generate audit reports, Tivoli zSecure suite offers a mainframe audit solution that provides analysis and reporting of mainframe events and automatic detection of exposures through extensive status auditing.

Mainframe security administration - For RACF administrators and IT managers who need to simplify and automate routine administrative tasks, and decentralize administration control, Tivoli zSecure suite offers a mainframe administration suite that enables efficient and effective RACF administration typically using less resources and, providing richer functionality, and helping address compliance initiatives. And by implementing a repeatable process for security management, Tivoli zSecure suite can help you reduce errors and improve the overall quality of services.

zSecure with legacy Consul clients

Tivoli zSecure suite V1.11 offers additional functionality for existing Consul customers. Contact your IBM representative or IBM Business Partner for more information on migrating to the latest zSecure version.


 
Back to topBack to top
 
Top rule
Program number
Bottom rule

Program             Program
number      VRM     name
 
5655-T01    1.11    IBM Tivoli zSecure Admin
5655-T02    1.11    IBM Tivoli zSecure Audit
5655-T05    1.11    IBM Tivoli zSecure CICS Toolkit
5655-T07    1.11    IBM Tivoli zSecure Command Verifier
5655-T09    1.11    IBM Tivoli zSecure Visual
5655-T11    1.11    IBM Tivoli zSecure Alert
5655-T15    1.11    IBM Tivoli Compliance Insight Manager Enabler
                      for z/OS

Product identification number

                    Subscription and
Program PID number  Support PID number
 
5655-T01            5655-T03
5655-T02            5655-T04
5655-T05            5655-T06
5655-T07            5655-T08
5655-T09            5655-T10
5655-T11            5655-T12
5655-T15            5655-T16

 
Back to topBack to top
 
Top rule
Education support
Bottom rule

Comprehensive education for IBM Tivoli products is offered through Worldwide Tivoli Education Delivery Services. A wide range of training options are available, including classes led by instructors, learning on demand, on-site training, and blended learning solutions.

For additional information, visit

http://www-306.ibm.com/software/tivoli/education/

 
Back to topBack to top
 
Top rule
Offering Information
Bottom rule

Product information is available via the Offering Information Web site

http://www.ibm.com/common/ssi

Business Partner information

If you are a Direct Reseller - System Reseller acquiring products from IBM, you may link directly to Business Partner information for this announcement. A PartnerWorld ID and password are required (use IBM ID).

https://www.ibm.com/partnerworld/mem/sla.jsp?num=209-385

 
Back to topBack to top
 
Top rule
Publications
Bottom rule

No hardcopy publications are shipped with these products.

Unlicensed publications

Unlicensed publications are available on the Tivoli zSecure Documentation CD provided with the products, with the exception of the Tivoli zSecure Quick Reference. This publication is available only from the Tivoli zSecure Information Center Web site at general availability.

Table 1 lists the unlicensed Tivoli zSecure suite V1.11 publications which are available in English. These publications can be viewed and downloaded from the Tivoli zSecure Information Center Web site at general availability.

National language unlicensed publications will be available from the Tivoli zSecure Information Center Web site 30 days after general availability.

Tivoli zSecure Information Center Web site

http://publib.boulder.ibm.com/infocenter/tivihelp/v2r1/topic/com. ibm.zsecure.doc/welcome.htm

English unlicensed publications

Title                                            Order number
 
IBM Tivoli zSecure
  Audit for ACF2 Getting Started                 GI11-8183-04
  Admin and Audit for RACF Getting Started       GI11-8184-04
  Alert User Reference Manual                    SC23-6547-05
  Visual Client Manual                           SC23-6548-03
  Visual Server Manual                           SC23-6549-03
  CICS Toolkit User's Guide                      SC23-6551-02
  Command Verifier User's Guide                  SC23-6550-03
  CARLa-Driven Components Installation and       SC23-6556-03
    Deployment Guide
  Messages Guide                                 GC23-9747-01
  Quick Reference in A4 Fold Format Booklet      SC23-6557-02
  Quick Reference Booklet in Letter Fold Format  SC23-6558-02
  Quick Reference Booklet in Standard Format     SC23-6559-02

Licensed publications

Table 2 lists the Tivoli zSecure suite V1.11 licensed publications which are available in English. These publications are only available to licensed users and are included on the Tivoli zSecure Documentation CD provided with your product order.

You can also download the licensed publications and the Documentation CD free of charge by signing in and verifying your license number at the following Web site

https://www14.software.ibm.com/webapp/iwm/web/preLogin.do?source=swg -consulesw

For an additional charge, you can order printed manuals or a manufactured Tivoli zSecure Documentation CD from the IBM Publications Center Web site. For ordering instructions, access the following

http://www.elink.ibmlink.ibm.com/publications/servlet/pbi.wss

National language versions of the licensed documentation are available from the same sources used to obtain the English versions.

English licensed publications

Title                                            Order number
 
IBM Tivoli zSecure
  Admin and Audit for RACF User Reference Manual LC23-6592-01
  Audit for ACF2 User Reference Manual           LC23-6546-03
  Audit for Top Secret User Reference Manual     LC23-9746-01
 
IBM Tivoli zSecure Suite
  Tivoli zSecure Documentation CD                LCD7-1387-06

IBM Publications Center

http://www.ibm.com/shop/publications/order

The Publications Center is a worldwide central repository for IBM product publications and marketing material with a catalog of 70,000 items. Extensive search facilities are provided. Payment options for orders are by credit card (in the U.S.) or customer number for 20 countries. A large number of publications are available online in various file formats, and they can all be downloaded by all countries, free of charge.


 
Back to topBack to top
 
Top rule
Technical information
Bottom rule

Specified operating environment

Hardware requirements

Minimum and recommended processor, disk space, and memory requirements for Tivoli zSecure suite V1.11:

               Minimum    Recommended
 
Processor      Z800       IBM System z9 or z10 Enterprise Class (EC)
                          or z9™ or z10 Business Class (BC)
 
Disk space     300 MB     450 MB
 
Memory         1 GB       2 GB
Software requirements

Tivoli zSecure suite V1.11 is supported in the following environments:

  • z/OS V1R8
  • z/OS V1R9
  • z/OS V1R10
  • z/OS V1R11

The zSecure products that include features for CA ACF2 and CA Top Secret support CA ACF2 R8, R9, and R12 and CA Top Secret R8, R9, and R12.

The program's specifications and specified operating environment information may be found in documentation accompanying the program, if available, such as a README file, or other information published by IBM, such as an announcement letter. Documentation and other program content may be supplied only in the English language.

Planning information

Packaging

Tivoli zSecure products are distributed with:

  • International Program License Agreement (Z125-3301)
  • License Information document
  • Tape
  • Publications (refer to the Publications section)

Security, auditability, and control

IBM Tivoli zSecure suite V1.11 uses the security and auditability features of the operating system software. The customer is responsible for evaluation, selection, and implementation of security features, administrative procedures, and appropriate controls in application systems and communication facilities.


 
Back to topBack to top
 
Top rule
Software Services
Bottom rule

IBM Software Services has the breadth, depth, and reach to manage your services needs. You can leverage the deep technical skills of our lab-based, software services team and the business consulting, project management, and infrastructure expertise of our IBM Global Services team. Also, we extend our IBM Software Services reach through IBM Business Partners to provide an extensive portfolio of capabilities. Together, we provide the global reach, intellectual capital, industry insight, and technology leadership to support a wide range of critical business needs.

To learn more about IBM Software Services or to contact a Software Services sales specialist, visit

http://www.ibm.com/software/sw-services/

 
Back to topBack to top
 
Top rule
IBM Tivoli Enhanced Value-Based Pricing
Bottom rule

IBM Tivoli software products are priced using Tivoli's Enhanced Value-based Pricing. The Enhanced Value-based Pricing system is based upon the Tivoli Environment-Managed Licensing Model, which uses a managed-environment approach -- whereby price is determined by what is managed rather than the number and type of product components installed.

For example, all servers monitored with Tivoli's monitoring product (IBM Tivoli Monitoring) require entitlements sufficient for those servers. Other Tivoli products may manage clients, client devices, agents, network nodes, users, or other items, and are licensed and priced accordingly.

Unlike typical systems management licensing models that require entitlements of specific software components to specific systems, the Tivoli Environment-Managed Licensing Model provides the customer flexibility to deploy its IBM Tivoli software products within its environment in a manner that can address and respond to the customer's evolving architecture. That is, as the architecture of a customer's environment changes, the customer's implementation of Tivoli software can be altered, as needed, without affecting the customer's license requirements (as long as the customer does not exceed its entitlements to the software).

Under Enhanced Value-based Pricing, licensing and pricing of server-oriented applications are determined based upon the server's use in the customer's environment. Typically, such applications are licensed and priced in a manner that corresponds to each installed and activated processor of the server managed by the IBM Tivoli application to help correlate price to value while offering a simple solution.

Where a server is physically partitioned, this approach is modified. This partitioning technique is the approach used with systems that have either multiple cards or multiple frames, each of which can be configured independently. For servers capable of physical partitioning (for example, IBM System p® Scalable POWERparallel Systems® servers, Sun Ultra servers, and HP Superdome servers), an entitlement is required for each processor in the physical partition being managed by the Tivoli application. For example, assume that a server has 24 processors installed in aggregate. If this server is not partitioned, entitlements are required for all 24 processors. If, however, it is physically partitioned into three partitions, each containing eight processors, and Tivoli products were managing only one of the three partitions, then entitlements would be required for the eight processors on the physical partition managed by the IBM Tivoli application.

For servers with virtual or logical partitions, entitlements are required for all installed and activated processors on the server. For each IBM Tivoli application managing a clustered environment, licensing is based on the cumulative number of installed and activated processors on each server in the cluster. Where the cluster includes physically partitioned servers, the considerations described above concerning physically partitioned servers apply as well.

Enhanced Value-based Pricing recognizes the convergence of RISC and UNIX, and Microsoft Windows® and Intel® technologies, in order to simplify your licensing requirements, and to provide a smoother, more scalable model. Pricing and licensing does not differentiate between non-System z server platforms or operating systems. For some products, this platform neutrality extends to System z and other host servers as well.

IBM Tivoli Enhanced Value-based Pricing terminology definitions

Authorized User

An Authorized User is one and only one individual (named or unnamed) within or outside your enterprise. A Proof of Entitlement (PoE) must be obtained for each individual user accessing the program in any manner. A program licensed under an Authorized User PoE may be installed on a single computer or server, and accessed by multiple users, provided that a PoE has been obtained for each individual user accessing the program either directly or indirectly (via a multiplexing program, device, or application server) through any means on behalf of the user.

Note that Authorized Users have unique specific identity and IDs cannot be shared. An ID can establish one or more connections and count as a single Authorized User. Specific information to security products:

  • An Authorized User of IBM Tivoli Federated Identity Manager is any ID that accesses an application or service managed or protected by IBM Tivoli Federated Identity Manager.
  • An Authorized User of IBM Tivoli Directory Integrator is one whose identity can be synchronized by IBM Tivoli Directory Integrator or that can access a connected system that can be synchronized by IBM Tivoli Directory Integrator.
  • An Authorized User of IBM Tivoli Identity Manager is any ID whose identity is recorded in the Tivoli Identity Manager identity store.
  • An Authorized User of IBM Tivoli Access Manager for e-business is any ID that accesses an application or service managed or protected by IBM Tivoli Access Manager for e-business.

Client device or client

A client device is a computing device that requests the execution of a set of commands, procedures, or applications from another computer system that is typically referred to as a server. Multiple client devices may share access to a common server. A client device generally has some processing capability or is programmable to allow a user to do work. Examples include, but are not limited to, notebook computers, desktop computers, desk side computers, technical workstations, appliances, automated teller machines, point-of-sale terminals, tills and cash registers, and kiosks.

Engine

An engine is also referred to as a central processor (CP) or processor. Engines for traditional workloads are called General Purpose CPs. Engines for Linux® workloads are called Integrated Facility for Linux (IFL) engines or Linux-only engines. Engines for Coupling Facility workloads are called ICF engines.

Enterprise

An enterprise is a person or single entity and those subsidiaries with more than 50 percent ownership.

External user

An external user is an Authorized User who is not part of the enterprise.

IBM IFL

This optional facility enables additional processing capacity exclusively for Linux workload, with no effect on the model designation of a System z or OS/390® server. Consequently, executing Linux workload on the IBM IFL will not, in most cases, result in any increased IBM software charges for z/OS, OS/390, VM, VSE, or TPF operating systems and applications. There is, as indicated, a charge associated with the IFL, and there may also be a charge for applications which run on the IFL.

The IFL may be dedicated to a single Linux-mode logical partition or it may be shared by multiple Linux-mode logical partitions. Installations should note that the Linux workspace enabled by this facility will not support any of the traditional S/390® operating systems (OS/390, TPF, VSE, or VM). Only Linux applications or Linux operating in conjunction with the Virtual Image Facility, an environment that operates within a logical partition or in native S/390 mode and provides the capability to create multiple Linux images, are supported by IBM S/390 IFL.

IBM Tivoli Directory Integrator connected system

A connected system is any directory, database, application, or file integrated or merged by IBM Tivoli Directory Integrator.

IBM Tivoli Storage Manager HSM for Windows terabyte (TB) capacity

IBM Tivoli Storage Manager HSM for Windows TB capacity includes primary HSM disk storage pool size combined with the amount of utilized HSM removable media storage pool. Storage pools are configured on the IBM Tivoli Storage Manager server.

IBM System Storage™ Archive Manager TB capacity

IBM System Storage Archive Manager TB capacity includes primary disk storage pool size combined with the amount of utilized primary removable media storage used by the IBM System Storage Archive Manager server.

Capacity does not include:

  • Copy storage pools for the space-managed data that reside on disk.
  • Copy storage pools for the space-managed data that reside on removable media.
  • Space used on the IBM Tivoli Storage Manager server for any purpose other than the primary storage of space-managed data.
  • Disk on the host being space managed.

A virtual tape library (VTL) is considered a removable media device, so capacity is based on utilization.

The minimum amount of capacity that can be purchased is 1 TB.

Partial capacity will be rounded up to the next whole number of TB.

Additional capacity must be added in increments of 1 TB.

IBM TotalStorage® Productivity Center TB capacity

A TB capacity is each individual TB of storage capacity managed by the IBM TotalStorage Productivity Center products. Managed capacity for the IBM TotalStorage Productivity Center for Replication and IBM TotalStorage Productivity Center for Replication Two Site BC is defined as the source device capacity. Only the source device capacity is included in this pricing definition (not the target device).

Managed processor (charging under full capacity in the managed environment)

Managed processor charges are based on the active processors on the machines in the computing environment affiliated with the program rather than on the server where the program is run. The managed processors which require PoEs are defined in the License Information's program-unique terms.

Notes

  1. IBM defines a physical processor in a computer as a functional unit that interprets and executes instructions. A physical processor consists of at least an instruction control unit and one or more arithmetic and logic units.
  2. Multicore technology allows two or more processors (commonly called cores) to be active on a single silicon chip. With multicore technology, IBM considers each core to be a physical processor. For example, in a dual-core chip, there are two physical processors residing on the single silicon chip.
  3. The program may not run on some or all of the processors for which PoEs are required by the program's valuation method.
  4. In the System z IFL environment, each IFL engine is considered a single physical processor.
  5. Threading, a technique which makes a single processor seem to perform as two or more, does not affect the count of physical processors.
  6. Where blade technology is employed, each blade is considered a separate server and charging is based upon the total number of processors on the blades with which the program is affiliated.
  7. Not all processors require the same number of Value Unit entitlements. To determine the number of Value Unit entitlements required, refer to the processor Value Unit conversion table on the Passport Advantage® Web site
    http://www.ibm.com/software/passportadvantage

Millions of Service Units (MSUs)

MSU is defined as millions of CPU service units per hour, which is the measure of capacity used to describe the computing power of the hardware processors on which S/390 or System z software runs. Processor MSU values are determined by the hardware vendor, IBM, or Software Compatible Vendors (SCVs).

For more detailed information about System z software pricing, visit

http://www-03.ibm.com/systems/z/resources/swprice/

Network node or node

Network nodes include routers, switches, hubs, and bridges that contain a network management agent. A single network node may contain any number of interfaces or ports.

Partitions

A server's resources (CPU, memory, I/O, interconnects, and buses) may be divided according to the needs of the applications running on the server. This partitioning can be implemented with physical boundaries (physical partitions) or logical boundaries (logical partitions).

Physical partitions are defined by a collection of processors dedicated to a workload and can be used with systems that have either multiple cards or multiple frames, each of which can be configured independently. In this method, the partitions are divided along hardware boundaries and processors, and the I/O boards, memory, and interconnects are not shared.

Logical partitions are defined by software rather than hardware and allocate a pool of processing resources to a collection of workloads. These partitions, while separated by software boundaries, share hardware components and run in one or more physical partitions.

Port

A port is the physical connection between a device and the network.

Processor (per processor charging under full capacity)

In full capacity charging, PoEs must be acquired for all activated processors (available for use) that are on the server where the program or a component of the program is run.

Notes

  1. IBM defines a physical processor in a computer as a functional unit that interprets and executes instructions. A physical processor consists of at least an instruction control unit and one or more arithmetic and logic units.
  2. Multicore technology allows two or more processors (commonly called cores) to be active on a single silicon chip. With multicore technology, IBM considers each core to be a physical processor. For example, in a dual-core chip, there are two physical processors residing on the single silicon chip.
  3. In the System z IFL environment, each IFL engine is considered a single physical processor.
  4. Threading, a technique which makes a single processor seem to perform as two or more, does not affect the count of physical processors.
  5. Where blade technology is employed, each blade is considered a separate server and charging is based upon the total number of processors on the blade on which the program is run.
  6. When a server is shipped with six processors, but two of them are inactive, four processors are active for the customer.
  7. Not all processors require the same number of Value Unit entitlements. To determine the number of Value Unit entitlements required, refer to the processor value unit conversion table on the Passport Advantage Web site
    http://www.ibm.com/software/passportadvantage

Server

A server is a computer system that executes requested procedures, commands, or applications to one or more user or client devices over a network. A PoE must be obtained for each server on which the program or a component of the program is run or for each server managed by the program. Where blade technology is employed, each blade is considered a separate server.

Stand-by or back-up systems

For programs running or resident on back-up machines, IBM defines three types of situations: cold, warm and hot. In cold and warm situations, a separate entitlement for the copy on the back-up machine is normally not required and typically no additional charge applies. In a hot backup situation, the customer needs to acquire other license or entitlements sufficient for that server. All programs running in backup mode must be solely under the customer's control, even if running at another enterprise's location.

As a practice, the following are definitions and allowable actions concerning the copy of the program used for backup purposes.

Cold: A copy of the program may reside, for back-up purposes, on a machine as long as the program is not started. There is no additional charge for this copy.

Warm: A copy of the program may reside for backup purposes on a machine and is started, but is idling, and is not doing any work of any kind. There is no additional charge for this copy.

Hot: A copy of the program may reside for backup purposes on a machine, is started, and is doing work. The customer must acquire a license or entitlements for this copy and there will generally be an additional charge.

Doing work includes, for example, production, development, program maintenance, and testing. It also could include other activities such as mirroring of transactions, updating of files, synchronization of programs, data or other resources (for example, active linking with another machine, program, database or other resource, and so on), or any activity or configurations that would allow an active hot switch or other synchronized switch over between programs, databases, or other resources to occur.

In the case of a program or system configuration that is designed to support a high availability environment by using various techniques (for example, duplexing, mirroring of files, or transactions, maintaining a heartbeat, active linking with another machine, program, database, or other resource), the program is considered to be doing work in the hot situation and a license or entitlement must be purchased.

Terabyte (T/TB)

1 TB of managed storage = 2 to the power of 40 bytes = 1,099,511,627,776 bytes, trillion bytes.

Tivoli Management Points

A Tivoli Management Point is a metric used to compute license quantities and is program specific.

Value Units

A Value Unit is a pricing charge metric for program license entitlements, which is based upon the quantity of a specific designated measurement used for a given program. Each program has a designated measurement. The most commonly used designated measurements are processor cores and MSUs. However, for select programs, there are other designated measurements such as servers, users, client devices, and messages. The number of Value Unit entitlements required for your specific implementation of the given program must be obtained from a conversion table associated with the program. You must obtain a PoE for the appropriate number of Value Unit entitlements for your implementation. The Value Unit entitlements of a given program cannot be exchanged, interchanged, or aggregated with Value Unit entitlements of another program. Whenever the designated measurement is a processor core, not all processors require the same number of Value Unit entitlements. To determine the number of Value Unit entitlements required, refer to the processor value unit conversion table on the Passport Advantage Web site

http://www.ibm.com/software/passportadvantage

Product and licensing Web sites

A complete list of IBM Tivoli products is available at

http://www.ibm.com/software/tivoli

System z software pricing examples (MSU-based)

Tivoli zSecure suite pricing explanation

zSecure programs use System z IPLA licensing, which means you have a one-time-charge (OTC) and an (optional) annual maintenance charge, called Subscription & Support (S&S). The following descriptions are used for System z IPLA licensing of zSecure programs: z/OS-based and Execution-based.

For customers with full capacity terms, "z/OS-based" means that the required license capacity of the program equals the MSU rated capacity of the machine where the program is running. For customers with sub-capacity terms, "z/OS-based" means that the required license capacity of the program equals the license capacity of z/OS (and z/OS.e) on the machine where the program is running.

For customers with full capacity terms, "Execution-based" means that the required license capacity of the program equals the MSU rated capacity of the machine where the program is running. For customers with sub-capacity terms, "Execution-based" means that the required license capacity of the program equals the capacity of the LPAR where the program is running.

The pricing metric for IPLA software on the mainframe is the Value Unit. Value Unit pricing is based upon MSUs for all Tivoli zSecure products, except for zSecure Manager for z/VM RACF which uses Value Units based upon engines (CPs or IFLs).

  • zSecure Admin - z/OS-based terms apply, meaning that in a full capacity environment this will be the full capacity number of MSUs of each machine where zSecure Admin is running, and in a sub-capacity environment this will be the MSUs reported for z/OS on the SCRT report for that machine.

    In a Sysplex environment the product must be licensed for the machine the zSecure Admin code is running on. If the zSecure Admin product is running on more than one machine then it must be licensed for each of those machines. However, in the RACF Remote Sharing network, it is possible for zSecure Admin to be running on one machine and provide RACF administration for multiple machines. This means that the zSecure Admin license entitlement on the one machine manages all of the machines in the RACF Remote Sharing network, with no actual zSecure Admin code running on the other machines. In situations like this, customers are not required to acquire zSecure Admin licenses for those other machines.

    In the situation where zSecure Admin can be used to report against other extracted RACF databases for comparison and/or merging, licensing of zSecure Admin is determined based upon whether or not zSecure Admin code is running on a machine. If zSecure Admin code is running on the machine, then that machine is required to be licensed. If zSecure Admin code is running on one machine which is reading the shared DASD or extracted databases of the other machines (where the code is not running), then the announced license rules do not require that customers acquire licenses for those other machines.

  • zSecure Audit - z/OS-based terms apply, meaning that in a full capacity environment this will be the full capacity number of MSUs of each machine where zSecure Audit is running. In a sub-capacity environment this will be the MSUs reported for z/OS on the SCRT report for that machine. In a Sysplex environment, the product can be licensed for just the machine that the zSecure Audit code is running on, even if it is running on behalf of the entire Sysplex configuration.
  • zSecure CICS Toolkit - Execution-based terms apply, meaning that in a full capacity environment this will be the full capacity number of MSUs of each machine where zSecure CICS Toolkit is running, and in a sub-capacity environment this will be the MSUs reported for the LPAR where zSecure CICS Toolkit is running.

    If the customer qualifies for sub-capacity IPLA charges, then they only need to license zSecure CICS Toolkit for the LPAR where it is running. If the customer requires zSecure CICS Toolkit code to execute on each machine, then each machine would need to be licensed. If zSecure CICS Toolkit can send a message via CICS or any other sending mechanism, and the zSecure CICS Toolkit is not running on another machine, then the announced license rules do not require that customers acquire licenses for that other machine.

  • zSecure Alert - Execution-based terms apply, meaning that in a full capacity environment this will be the full capacity number of MSUs of each machine where zSecure Alert is running, and in a sub-capacity environment this will be the MSUs reported for the LPAR where zSecure Alert is running.
  • zSecure Visual - z/OS-based terms apply, meaning that in a full capacity environment this will be the full capacity number of MSUs of each machine where zSecure Visual is running, and in a sub-capacity environment this will be the MSUs reported for z/OS on the SCRT report for that machine. In a Sysplex environment the product can be licensed for the machine the zSecure Visual code is running on, even if it is running on behalf of the entire Sysplex configuration.
  • zSecure Command Verifier - z/OS-based terms apply, meaning that in a full capacity environment this will be the full capacity number of MSUs of each machine where zSecure Command Verifier is running, and in a sub-capacity environment this will be the MSUs reported for z/OS on the SCRT report for that machine. In a Sysplex environment the product can be licensed for the machine the zSecure Command Verifier code is running on, even if it is running on behalf of the entire Sysplex configuration.

Tivoli zSecure suite pricing examples

The following pricing example should be used to determine required license entitlements for the following software products for System z:

System z server

1,000 MSU System z server with 25 engines

All products for this example employ Value Unit slope Value Unit Exhibit 020 (VUE020). Translation from MSUs to Value Units:

VUE020

           MSUs          Value Units/MSU
 
Base       1-3           1.00
Tier A     4-45           .15
Tier B     46-175         .08
Tier C     176-315        .04
Tier D     316+           .03

If the customer has installed 1,000 MSUs, the applicable number of Value Units will be:

                 Value
Level    MSUs    Units/MSU   Value Units
 
Base       3     1.00         3.00
Tier A    42     0.15         6.30
Tier B   130     0.08        10.40
Tier C   140     0.04         5.60
Tier D   685     0.03        20.55
 
Total  1,000                 45.85

When calculating the total number of Value Units, the sum is rounded up to the next integer. In this example, the customer will need to license 46 Value Units.

Note: IBM RACF for z/OS (a separate IBM MLC offering) or a comparable competitive offering (CA ACF2 or CA Top Secret) is a prerequisite for Tivoli zSecure suite. For more information on RACF, refer to

http://www.ibm.com/racf

Scenario 1: MSU-based pricing

Transaction 1

Enterprise ABC initially wants to work with the following system configuration:

On one System z server with 1,000 MSUs, they want to run Tivoli zSecure Audit and zSecure Alert. The same calculation applies to both Audit and Alert components:

                 Value
Level    MSUs    Units/MSU   Value Units
 
Base       3     1.00         3.00
Tier A    42     0.15         6.30
Tier B   130     0.08        10.40
Tier C   140     0.04         5.60
Tier D   685     0.03        20.55
 
Total  1,000                 45.85

The customer must purchase 46 Value Units for Audit and 46 Value Units for Alert.

Transaction 2

After the initial purchase, enterprise ABC wants to expand their use of the Tivoli zSecure suite to include the Tivoli zSecure Command Verifier, Admin, and Visual, along with the Tivoli Compliance Insight Manager Enabler for z/OS. IBM Tivoli Compliance Insight Manager is sold separately through distributed pricing structures; refer to the separate software announcement and pricing example for Tivoli Compliance Insight Manager.

The same calculation applies to each of these components:

                 Value
Level    MSUs    Units/MSU   Value Units
 
Base       3     1.00         3.00
Tier A    42     0.15         6.30
Tier B   130     0.08        10.40
Tier C   140     0.04         5.60
Tier D   685     0.03        20.55
 
Total  1,000                 45.85

The customer must purchase 46 Value Units for each of Command Verifier, Admin, Visual, and Tivoli Compliance Insight Manager Enabler.


 
Back to topBack to top
 
Top rule
Ordering information
Bottom rule

The programs in this announcement all have Value Unit-based pricing.

Program
number      Program name                           Value Unit exhibit
 
5655-T01   IBM Tivoli zSecure Admin                VUE020
5655-T02   IBM Tivoli zSecure Audit                VUE020
5655-T05   IBM Tivoli zSecure CICS Toolkit         VUE020
5655-T07   IBM Tivoli zSecure Command Verifier     VUE020
5655-T09   IBM Tivoli zSecure Visual               VUE020
5655-T11   IBM Tivoli zSecure Alert                VUE020
5655-T15   IBM Tivoli Compliance Insight Manager   VUE020
               Enabler for z/OS

For each System z IPLA program with Value Unit pricing, the quantity of that program needed to satisfy applicable IBM terms and conditions is referred to as the required license capacity. Your required license capacity is based upon the following factors:

  • The System z IPLA program you select
  • The applicable Value Unit Exhibit
  • The applicable terms
  • Whether your current mainframes are full capacity or sub-capacity

Value Unit exhibit VUE020

                         Value
Level    Minimum Maximum Units/MSU
 
Base       1       3     1
Tier A     4      45     0.15
Tier B    46     175     0.08
Tier C   176     315     0.04
Tier D   316       +     0.03

Value Units for mainframes without MSU ratings:

               Value
HW             Units/machine
 
MP3000 H30     3
MP3000 H50     4
MP3000 H70     6
ESL Models     1

Ordering z/OS through the Internet

ShopzSeries provides an easy way to plan and order your z/OS ServerPac or CBPDO. It will analyze your current installation, determine the correct product migration, and present your new configuration based on z/OS. Additional products can also be added to your order (including determination of whether all product requisites are satisfied). ShopzSeries is available in the U.S. and several countries in Europe. In countries where ShopzSeries is not available yet, contact your IBM representative (or IBM Business Partner) to handle your order via the traditional IBM ordering process. For more details and availability, visit the ShopzSeries Web site at

http://www14.software.ibm.com/webapp/ShopzSeries/ShopzSeries.jsp
Single version charging

To elect single version charging, you must notify and identify to IBM the prior program and replacement program, and the machine the programs are operating on.

Current licensees

Current licensees, with support in effect, will receive instructions on how to order this update.

Current licensees of Tivoli zSecure suite V1.11 can order the new distribution medium via MES by specifying the desired distribution medium feature number.

New licensees

Orders for new licenses will be accepted now.

Shipment will begin on the planned availability date.

Basic license

This table should be used for all zSecure PIDs

 
     VUE020       MSUs         Value Units/MSU
       Base        1-3         1.00
       Tier A      4-45        0.15
       Tier B     46-175       0.08
       Tier C    176-315       0.04
       Tier D    316+          0.03

To order, specify the program product number and the appropriate license or charge option. Also, specify the desired distribution medium. To suppress shipment of media, select the license-only option in CFSW.

Ordering information for Value Unit pricing - 5655-T01

Program name:  IBM Tivoli zSecure Admin V1.11
Program PID:  5655-T01
 
Entitlement                                
identifier   Description       License option/Pricing metric
 
S01471B      zSecure Admin     Basic OTC, per Value Unit
 
 
Orderable    
supply ID    Language          Distribution medium
 
S015SZS      Multilingual      3480 tape cartridge
 
Subscription and Support PID:  5655-T03
 
Entitlement                          
identifier   Description        License option/Pricing metric
 
S01471M      zSecure Admin      Basic ASC, per Value Unit SW S&S
              S&S               no charge, decline SW S&S
                                per MSU SW S&S registration
 
Orderable     
supply ID    Language           Distribution medium
 
S015T26      Multilingual       Hardcopy publication
 

Ordering information for On/Off Capacity on Demand (On/Off CoD)

IBM Tivoli zSecure Admin is eligible for On/Off CoD with a temporary use charge calculated based on MSUs per-day usage.

Program name:  IBM Tivoli zSecure Admin V1.11
Program PID:  5655-T01
 
Entitlement                          
identifier      Description     License option/Pricing metric
 
S01471B         zSecure Admin   Basic OTC, per MSU-day TUC

Ordering information for Value Unit Pricing (5655-T02)

Program name:  IBM Tivoli zSecure Audit V1.11
Program PID:  5655-T02
 
Entitlement                                 
identifier   Description            License option/Pricing metric
 
S01471C      RACF                   Basic OTC, per Value Unit
S01471D      ACF2                   Basic OTC, per Value Unit
S01471F      Top Secret             Basic OTC, per Value Unit
 
Orderable     
supply ID    Language/Description   Distribution medium
 
S015T29      Multilingual RACF     3480 tape cartridge
S015T27      Multilingual ACF2
S015T28      Multilingual Top SecretSubscription and Support PID:  5655-T04
 
Entitlement                          
identifier   Description            License option/Pricing metric
 
S01471N      RACF S&S               Basic ASC, per Value Unit SW S&S
                                    no charge, decline SW S&S
                                    per MSU SW S&S registration
 
S01471P      ACF2 S&S               Basic ASC, per Value Unit SW S&S
                                    no charge, decline SW S&S
                                    per MSU SW S&S registration
 
S01471R      Top Secret S&S         Basic ASC, per Value Unit SW S&S
                                    no charge, decline SW S&S
                                    per MSU SW S&S registration
 
Orderable     
supply ID    Language/Description   Distribution medium
 
S015TT2      Multilingual RACF     Hardcopy publication
S015TT3      Multilingual ACF2
S015TT4      Multilingual Top Secret
 

Ordering information for On/Off Capacity on Demand (On/Off CoD)

IBM Tivoli zSecure Audit is eligible for On/Off CoD with a temporary use charge calculated based on MSUs per-day usage.

Program name:  IBM zSecure Audit V1.11
Program PID:  5655-T02
 
Entitlement                          
identifier      Description          License option/Pricing metric
 
S01471C         RACF                 Basic OTC, per MSU-day TUC
S01471D         ACF2                 Basic OTC, per MSU-day TUC
S01471F         Top Secret           Basic OTC, per MSU-day TUC

Ordering information for Value Unit pricing - 5655-T05

Program name:  IBM Tivoli zSecure CICS Toolkit V1.11
Program PID:  5655-T05
 
Entitlement                                 
identifier     Description             License option/Pricing metric
 
S01471S        zSecure CICS            Basic OTC, per Value Unit
                Toolkit  
 
Orderable     
supply ID      Language/Description    Distribution medium
 
S015T2B        Multilingual            3480 tape cartridge
 
Subscription and Support PID:  5655-T06
 
Entitlement                          
identifier   Description              License option/Pricing metric
 
S01472T      zSecure CICS Toolkit     Basic ASC, per Value Unit SW S&S
             S&S                      no charge, decline SW S&S
                                      per MSU SW S&S registration
 
Orderable     
supply ID   Language/Description      Distribution medium
 
S015TP6     Multilingual              Hardcopy publication

Ordering information for On/Off Capacity On Demand (ON/OFF COD)

IBM Tivoli zSecure Audit is eligible for On/Off CoD with a temporary use charge calculated based on MSUs per-day usage.

Program name:  IBM Tivoli zSecure CICS Toolkit V1.11
Program PID:  5655-T05
 
Entitlement                          
identifier    Description          License option/Pricing metric
 
S01471S       zSecure CICS         Basic OTC, per MSU-day TUC
               Toolkit

Ordering information for Value Unit pricing - 5655-T07

Program name:  IBM Tivoli zSecure Command Verifier V1.11
Program PID:  5655-T07
 
Entitlement                                 
identifier   Description           License option/Pricing metric
 
S01471T      zSecure Command       Basic OTC, per Value Unit
              Verifier
 
Orderable    Language              Distribution medium
supply ID
 
S015T8M      Multilingual          3480 tape cartridge
 
Subscription and Support PID:  5655-T08
 
Entitlement                          
identifier   Description           License option/Pricing metric
 
S01471V      zSecure Command       Basic ASC, per Value Unit SW S&S
             Verifier S&S          no charge, decline SW S&S
                                   per MSU SW S&S registration 
Orderable     
supply ID    Language              Distribution medium
 
S015TPD      Multilingual          Hardcopy publication
 

Ordering information for On/Off Capacity on Demand (On/Off CoD)

IBM Tivoli zSecure Command Verifier is eligible for On/Off CoD with a temporary use charge calculated based on MSUs per-day usage.

Program name:  IBM zSecure Command Verifier V1.11
Program PID:  5655-T07
 
Entitlement                          
identifier      Description          License option/Pricing metric
 
S01471T         zSecure Command      Basic OTC, per MSU-day TUC
                 Verifier

Ordering information for Value Unit pricing - 5655-T09

Program name:  IBM Tivoli zSecure Visual V1.11
Program PID:  5655-T09
 
Entitlement                                 
identifier     Description            License option/Pricing metric
 
S01471X        zSecure Visual         Basic OTC, per Value Unit
 
 
Orderable 
supply ID      Language               Distribution medium
 
S015T8R        Multilingual           3480 tape cartridge
Subscription and Support PID:  5655-T10
 
Entitlement                          License option/
identifier   Description             Pricing metric
 
S014721      zSecure Visual S&S      Basic ASC, per Value Unit SW S&S
                                     no charge, decline SW S&S
                                     per MSU SW S&S registration 
Orderable 
supply ID    Language                  Distribution medium
 
S015TPX      Multilingual              Hardcopy publication
 

Ordering information for On/Off Capacity on Demand (On/Off CoD)

IBM Tivoli zSecure Visual is eligible for On/Off CoD with a temporary use charge calculated based on MSUs per-day usage.

Program name:  IBM Tivoli zSecure Visual V1.11
Program PID:  5655-T09
 
Entitlement                          
identifier     Description          License option/Pricing metric
 
S01471X        zSecure Visual       Basic OTC, per MSU-day TUC

Ordering information for Value Unit pricing - 5655-T11

Program name:  IBM Tivoli zSecure Alert V1.11
Program PID:  5655-T11
 
Entitlement                                 
identifier    Description            License option/Pricing metric
 
S014725       RACF                   Basic OTC, per Value Unit
S014728       ACF2                   Basic OTC, per Value Unit
 
Orderable 
supply ID    Language/Description   Distribution medium
 
S015TDS      Multilingual RACF      3480 tape cartridge
S015TDR      Multilingual ACF2
Subscription and Support PID:  5655-T12
 
Entitlement                          
identifier   Description             License option/Pricing metric
 
S014733      RACF S&S                Basic ASC, per Value Unit SW S&S
                                     no charge, decline SW S&S
                                     per MSU SW S&S registration
 
S014736      ACF2 S&S                Basic ASC, per Value Unit SW S&S
                                     no charge, decline SW S&S
                                     per MSU SW S&S registration
 
Orderable 
supply ID   Language/Description     Distribution medium
 
S015TPZ     Multilingual RACF         Hardcopy publication
S015TR0     Multilingual ACF2
 

Ordering information for On/Off Capacity on Demand (On/Off CoD)

IBM Tivoli zSecure Alert is eligible for On/Off CoD with a temporary use charge calculated based on MSUs per-day usage.

Program name:  IBM Tivoli zSecure Alert V1.11
Program PID:  5655-T11
 
Entitlement                          
identifier      Description          License option/Pricing metric
 
S014725         RACF                 Basic OTC, per MSU-day TUC
S014728         ACF2                 Basic OTC, per MSU-day TUC
 

Ordering information for Value Unit pricing - 5655-T15

Program name:  IBM Tivoli Compliance Insight Manager Enabler for z/OS
V1.11
Program PID:  5655-T15
 
Entitlement                          
identifier   Description             License option/Pricing metric
 
S01473W      RACF                    Basic OTC, per Value Unit
S014748      ACF2                    Basic OTC, per Value Unit
S014749      Top Secret              Basic OTC, per Value Unit
S01474K      DB2                     Basic OTC, per Value Unit
S015TNJ      CICS                    Basic OTC, per Value Unit
 
Orderable 
supply ID    Language/Description    Distribution medium
 
S015TK1      Multilingual RACF       3480 tape cartridge
S015TK2      Multilingual ACF2
S015TK3      Multilingual Top Secret
S015TK4      Multilingual DB2
S015TK6      Multilingual CICS 
Subscription and Support PID:  5655-T16
 
Entitlement                          
identifier   Description             License option/Pricing metric
 
S01473K      RACF S&S                Basic ASC, per Value Unit SW S&S
                                     no charge, decline SW S&S
S01474B      ACF2 S&S                Basic ASC, per Value Unit SW S&S
                                     no charge, decline SW S&S
S01474C      Top Secret S&S          Basic ASC, per Value Unit SW S&S
                                     no charge, decline SW S&S
S01474W      DB2 S&S                 Basic ASC, per Value Unit SW S&S
                                     no charge, decline SW S&S
S015TNK     CICS S&S                 Basic ASC, per Value Unit SW S&S
                                     no charge, decline SW S&S
 
Orderable 
supply ID    Language/Description    Distribution medium 
 
S015TNS      Multilingual RACF       Hardcopy publication
S015TNR      Multilingual ACF2
S015TNP      Multilingual Top Secret
S015TNN      Multilingual DB2
S015TNM      Multilingual CICS

Subscription and Support

Subscription and Support must be ordered to receive voice technical support via telephone during normal business hours, and future releases and versions, at no additional charge. The capacity of Subscription and Support (for example, Value Units or number of processors) must be the same as the capacity ordered for the product licenses.

To order, specify the Subscription and Support program product number and the appropriate license or charge option.

IBM is also providing Subscription and Support for these products, via a separately purchased offering, under the terms of the IBM International Agreement for Acquisition of Support Maintenance (IAASM). This offering:

  • Includes and extends the support services provided in the base support to include technical support via telephone during normal business hours.
  • Entitles customers to future releases and versions, at no additional charge. Note that the customer is not entitled to new products.

When Subscription and Support is ordered, the charges will automatically renew annually unless cancelled by the customer.

Customized Offerings

Product deliverables are shipped only via Customized Offerings (for example, CBPDO, ServerPac, SystemPac®).

CBPDO and ServerPac are offered for Internet delivery, where ShopzSeries product ordering is available. Internet delivery of ServerPac may help improve automation and software delivery time. For more details on Internet delivery, refer to the ShopzSeries help information at

http://www.software.ibm.com/ShopzSeries

Media type for this software product is chosen during the Customized Offerings ordering process. Based on your customer environment, it is recommended that the highest possible density tape media is selected. Currently offered media types are:

  • CBPDOs - 3480, 3480 Compressed, 3490E, 3590, 35921
  • ServerPacs - 3480, 3480 Compressed, 3490E, 3590, 35921
  • SystemPacs - 3480, 3480 Compressed, 3490E, 3590, 35921
1
3592 is highest density media. Selecting 3592 will ship the fewest number of media.

Once a product becomes generally available, it will be included in the next ServerPac and SystemPac monthly update.

Production of software product orders will begin on the planned general availability date.

  • CBPDO shipments will begin one week after general availability.
  • ServerPac shipments will begin two weeks after inclusion in ServerPac.
  • SystemPac shipments will begin four weeks after inclusion in SystemPac due to additional customization, and data input verification.

 
Back to topBack to top
 
Top rule
Terms and conditions
Bottom rule

The information provided in this announcement letter is for reference and convenience purposes only. The terms and conditions that govern any transaction with IBM are contained in the applicable contract documents such as the IBM International Program License Agreement, IBM International Passport Advantage Agreement, and the IBM Agreement for Acquisition of Software Maintenance.

Licensing

IBM International Program License Agreement including the License Information document and Proof of Entitlement (PoE) govern your use of the program. PoEs are required for all authorized use.

Agreement for Acquisition of Software Maintenance

The IBM Agreement for Acquisition of Software Maintenance (Z125-6011)applies for Software Subscription and Support (Software Maintenance) and does not require customer signatures:

These programs are licensed under the IBM Program License Agreement (IPLA) and the associated Agreement for Acquisition of Software Maintenance, which provide for support with ongoing access to releases and versions of the program. These programs have a one-time license charge for use of the program and an annual renewable charge for the enhanced support that includes telephone assistance (voice support for defects during normal business hours), as well as access to updates, releases, and versions of the program as long as support is in effect.

IBM System z Operational Support Services - SoftwareXcel is an option if you desire added services.

License Information form number
Product                                             LI Form Number
 
IBM Tivoli zSecure Admin V1.11                      GC23-7976-04
IBM Tivoli zSecure Audit V1.11                      GC23-7977-03
IBM Tivoli zSecure CICS Toolkit V1.11               GC23-7981-02
IBM Tivoli zSecure Command Verifier V1.11           GC23-7982-03
IBM Tivoli zSecure Visual V1.11                     GC23-7979-03
IBM Tivoli zSecure Alert V1.11                      GC23-7978-03
IBM Tivoli Compliance Insight Manager Enabler       GC23-7980-03
 for z/OS V1.11

The program's License Information will be available for review on the IBM Software License Agreement Web site

http://www.ibm.com/software/sla/sladb.nsf
Limited warranty applies

Yes

Limited warranty

IBM warrants that when the program is used in the specified operating environment, it will conform to its specifications. The warranty applies only to the unmodified portion of the program. IBM does not warrant uninterrupted or error-free operation of the program or that IBM will correct all program defects. You are responsible for the results obtained from the use of the program.

IBM provides you with access to IBM databases containing information on known program defects, defect corrections, restrictions, and bypasses at no additional charge. For further information, consult the IBM Software Support Handbook found at

http://www.ibm.com/support/handbook

IBM will maintain this information for at least one year after the original licensee acquires the program (warranty period).

Program support

Enhanced support, called Subscription and Support, includes telephone assistance, as well as access to updates, releases, and versions of the program as long as support is in effect. You will be notified of discontinuance of support with 12 months' notice.

Money-back guarantee

If for any reason you are dissatisfied with the program and you are the original licensee, you may obtain a refund of the amount you paid for it, if within 30 days of your invoice date you return the program and its PoE to the party from whom you obtained it. If you downloaded the program, you may contact the party from whom you acquired it for instructions on how to obtain the refund.

For clarification, note that for programs acquired under any of IBM's On/Off Capacity on Demand (On/Off CoD) software offerings, this term does not apply since these offerings apply to programs already acquired and in use by you.

Authorization for use on home/Portable computer

You may not copy and use this program on another computer without paying additional license fees.

Volume orders (IVO)

No

Passport Advantage applies

No

Usage restriction

Yes. Usage is limited to the quantity of Value Units licensed.

For additional information, refer to the License Information document that is available on the IBM Software License Agreement Web site

http://www.ibm.com/software/sla/sladb.nsf
Software Subscription and Support (Software Maintenance) applies

No. For operating system software, the revised IBM Operational Support Services - SoftwareXcel offering will provide support for those operating systems and associated products that are not available with the Software Subscription and Support (Software Maintenance) offering.

This will ensure total support coverage for your enterprise needs, including IBM and selected non-IBM products. For complete lists of products supported under both the current and revised offering, visit

http://www.ibm.com/services/sl/products
IBM Operational Support Services - SoftwareXcel

Yes

System i Software Maintenance applies

No

Variable charges apply

Yes

Educational allowance available

Yes. A 15% education allowance applies to qualified education institution customers.

Sub-capacity terms and conditions

For each System z IPLA program with Value Unit pricing, the quantity of that program needed to satisfy applicable IBM terms and conditions is referred to as the required license capacity. Your required license capacity is based upon the following factors:

  • The System z IPLA program you select
  • The applicable Value Unit Exhibit
  • The applicable terms
  • Whether your current mainframes are full capacity or sub-capacity

For more information on the Value Unit Exhibit for the System z IPLA program you selected, refer to the Ordering information section.

Program
number      Program name                        Terms
 
5655-T01  IBM Tivoli zSecure Admin              z/OS-based
5655-T03  IBM Tivoli zSecure Admin              z/OS based
5655-T02  IBM Tivoli zSecure Audit              z/OS-based
5655-T04  IBM Tivoli zSecure Audit              z/OS-based
5655-T07  IBM Tivoli zSecure Command Verifier   z/OS-based
5655-T08  IBM Tivoli zSecure Command Verifier   z/OS-based
5655-T09  IBM Tivoli zSecure Visual             z/OS-based
5655-T10  IBM Tivoli zSecure Visual             z/OS-based
5655-T05  IBM Tivoli zSecure CICS Toolkit       Execution-based
5655-T06  IBM Tivoli zSecure CICS Toolkit       Execution-based
5655-T11  IBM Tivoli zSecure Alert              Execution-based
5655-T12  IBM Tivoli zSecure Alert              Execution-based
Full-capacity mainframes

In cases where full capacity is applicable, the following terms apply.

Execution-based, z/OS based, full machine based: The required capacity of a System z IPLA program with these terms equals the MSU-rated capacity of the machines where the System z IPLA program executes.

For more information on mainframe MSU-rated capacities, visit

http://www-1.ibm.com/servers/eserver/zseries/library/swpriceinfo/

Reference-based: The required license capacity of a System z IPLA program with these terms equals the license capacity of the applicable monthly license charge (MLC) program. This MLC program is called the parent program.

Sub-capacity mainframes

In cases where sub-capacity is applicable, the following terms apply.

Execution-based: The required capacity of a System z IPLA sub-capacity program with these terms equals the capacity of the LPARs where the System z IPLA program executes.

z/OS-based: The required license capacity of a System z IPLA program with these terms equals the license capacity of z/OS on the machines where the System z IPLA program executes.

Reference-based: The required license capacity of a System z IPLA program with these terms equals the license capacity of the applicable monthly license charge (MLC) program. This MLC program is called the parent program.

Full-machine-based: The required license capacity of a System z IPLA program with full machine based terms equals the MSU-rated capacity of the machines where the System z IPLA program executes.

For more information on mainframe MSU-rated capacities, refer to The IBM System z Machines Exhibit (Z125-3901), or visit the Mainframes section of the System z Exhibits Web site

http://ibm.com/zseries/library/swpriceinfo/

For more information on sub-capacity System z IPLA terms and conditions, refer to Software Announcement 204-184, dated August 10, 2004.

For additional information for products with reference-based terms, System z IPLA sub-capacity programs with reference-based terms adds value to the parent program across the environment, regardless of where in the environment the System z IPLA program executes.

An environment is defined as either a single or stand-alone machine or a qualified Parallel Sysplex®. You may have one or more different environments across the enterprise. To determine the required license capacity for each System z IPLA program with referenced-based terms, each environment should be assessed separately.

When a System z IPLA sub-capacity program with reference-based terms is used in a qualified Parallel Sysplex environment, the required license capacity of the System z IPLA program must equal with the license capacity of the parent program across the Parallel Sysplex. Qualified Parallel Sysplex refers to one:

  • That meets the criteria defined in Hardware Announcement 198-001, dated January 13, 1998
  • Where MLC pricing is aggregated across the sysplex
Sub-capacity eligibility

To be eligible for sub-capacity charging on select System z IPLA programs, you must first implement and comply with all terms of either sub-capacity Workload License Charges (WLC) or sub-capacity Entry Workload License Charges (EWLC). To implement sub-capacity WLC or EWLC, a machine must be System z (or equivalent). On that machine:

  • All instances of the OS/390 operating system must be migrated to the z/OS operating systems
  • Any licenses for the OS/390 operating system must be discontinued
  • All instances of the z/OS operating systems must be running in z/Architecture® (64-bit) mode

For that machine, you must create and submit a Sub-Capacity Report to IBM each month. Sub-Capacity Reports must be generated using the Sub-Capacity Reporting Tool (SCRT). For additional information or to obtain a copy of SCRT, visit the System z Software Pricing Web site

http://ibm.com/zseries/swprice

You must comply with all of the terms of the WLC or EWLC offering, whichever is applicable:

  • The complete terms and conditions of sub-capacity WLC are defined in the IBM Customer Agreement - Attachment for System z Workload License Charges (Z125-6516)
  • The complete terms and conditions for sub-capacity EWLC are defined in the IBM Customer Agreement - Attachment for IBM System z 890 and 800 License Charges (Z125-6587)

Additionally, you must sign and comply with the terms and conditions specified in the amendment to the IPLA contract - Amendment for IBM System z9® and System z Programs Sub-Capacity Pricing (Z125-6929). Once the amendment is signed, the terms in the amendment replace any and all previous System z IPLA sub-capacity terms and conditions.

IBM Getting Started Sub-capacity Pricing for z/OS IPLA Software applies.

Sub-capacity utilization determination

Sub-capacity utilization is determined based on the utilization of an eligible operating system and machine (for example, z/OS running in z/Architecture (64-bit) mode on a System z ((or equivalent) server). server).

On/Off Capacity on Demand (CoD)

To be eligible for On/Off CoD pricing, you must be enabled for temporary capacity on the corresponding hardware, and the required contract, Attachment for Customer Initiated Upgrade and IBM eServer™ On/Off Capacity on Demand - Software (Z125-6611) must be signed prior to use.


 
Back to topBack to top
 
Top rule
IBM Electronic Services
Bottom rule

IBM has transformed its delivery of hardware and software support services to help you achieve higher system availability. Electronic Services is a Web-enabled solution that offers an exclusive, no-additional-charge enhancement to the service and support available for IBM servers. These services are designed to provide the opportunity for greater system availability with faster problem resolution and preemptive monitoring. Electronic Services comprises two separate, but complementary, elements: Electronic Services news page and Electronic Services Agent.

The Electronic Services news page is a single Internet entry point that replaces the multiple entry points traditionally used to access IBM Internet services and support. The news page enables you to gain easier access to IBM resources for assistance in resolving technical problems.

The Electronic Service Agent™ is no-additional-charge software that resides on your server. It monitors events and transmits system inventory information to IBM on a periodic, client-defined timetable. The Electronic Service Agent automatically reports hardware problems to IBM. Early knowledge about potential problems enables IBM to deliver proactive service that may result in higher system availability and performance. In addition, information collected through the Service Agent is made available to IBM service support representatives when they help answer your questions or diagnose problems. Installation and use of IBM Electronic Service Agent for problem reporting enables IBM to provide better support and service for your IBM server.

To learn how Electronic Services can work for you, visit

http://www.ibm.com/support/electronic

 
Back to topBack to top
 
Top rule
Prices
Bottom rule

Information on charges is available at Web site

http://www.ibm.com/support

In the Electronic tools category, select the option for Purchase/upgrade tools.

Passport Advantage

For Passport Advantage and charges, contact your IBM representative or your authorized IBM Business Partner. Additional information is also available at

http://www.ibm.com/software/passportadvantage

Business Partner information:

If you are an IBM Business Partner -- Distributor for Workstation Software acquiring products from IBM, you may link to Passport Advantage Online for resellers where you can obtain Business Partner pricing information. An IBM ID and password are required.

https://www.ibm.com/software/howtobuy/passportadvantage/paoreseller

 
Back to topBack to top
 
Top rule
Order now
Bottom rule

To order, contact your local IBM representative or your IBM Business Partner.

To identify your local IBM Business Partner or IBM representative, call 800-IBM-4YOU (426-4968). For more information, contact the Americas Call Centers.

Phone:     800-IBM-CALL (426-2255)
Fax:       800-2IBM-FAX (242-6329)
 
For IBM representative: callserv@ca.ibm.com
 
For IBM Business Partner: pwswna@us.ibm.com 
 Mail:      IBM Teleweb Customer Support
            ibm.com® Sales Execution Center, Americas North
            3500 Steeles Ave. East, Tower 3/4
            Markham, Ontario
            Canada  L3R 2Z1
 
 Reference: LE001

The Americas Call Centers, our national direct marketing organization, can add your name to the mailing list for catalogs of IBM products.

Note: Shipments will begin after the planned availability date.

Trademarks

DFSMS, MVS, z9, System Storage, eServer and Electronic Service Agent are trademarks of IBM Corporation in the United States, other countries, or both.

Tivoli, z/OS, RACF, CICS, DB2, IBM, OMEGAMON, WebSphere, z/VM, System z, System p, Scalable POWERparallel Systems, OS/390, S/390, TotalStorage, Passport Advantage, SystemPac, Parallel Sysplex, z/Architecture, System z9 and ibm.com are registered trademarks of IBM Corporation in the United States, other countries, or both.

UNIX is a registered trademark of The Open Group in the United States and other countries.

Microsoft and Windows are registered trademarks of Microsoft Corporation in the United States, other countries, or both.

Intel is a registered trademark of Intel Corporation or its subsidiaries in the United States and other countries.

Linux is a registered trademark of Linus Torvalds in the United States, other countries, or both.

Other company, product, and service names may be trademarks or service marks of others.

Terms of use

IBM products and services which are announced and available in your country can be ordered under the applicable standard agreements, terms, conditions, and prices in effect at the time. IBM reserves the right to modify or withdraw this announcement at any time without notice. This announcement is provided for your information only. Additional terms of use are located at:

http://www.ibm.com/legal/us/en/

For the most current information regarding IBM products, consult your IBM representative or reseller, or visit the IBM worldwide contacts page

http://www.ibm.com/planetwide/us/

 

Back to topBack to top
 
Bottom grey rule
 
Printable version Printable version