IBM Tivoli zSecure V1.9 suite extends compliance and audit capabilities on the mainframe while simplifying administration
IBM United States Software Announcement 207-338December 11, 2007
|
|
| At a glance |
IBM Tivoli zSecure V1.9 suite can help you enhance the security of mainframe systems by:
- Automating routine administrative tasks to help reduce costs and improve productivity
- Monitoring and auditing incidents to help detect and prevent security exposures
- Seamlessly integrating with an enterprise-wide view of audit and compliance efforts
Tivoli zSecure V1.9 suite also provides:
- Currency with z/OS V1.9, including SMF Logger Stream Input and Digital Certificate enhancements
- Key RAS function, including error log integrity and data collection resiliency
For ordering, contact:
Your IBM representative, an IBM Business Partner, or IBM Americas Call Centers at
800-IBM-CALL
(Reference: YE001).
Back to top
|
|
| Overview |
The IBM Tivoli® zSecure V1.9 for z/OS® suite consists of multiple modular components designed to help you administer your mainframe security server, monitor for threats, audit usage and configurations, and enforce policy compliance.
Administration, provisioning, and management components can significantly reduce administration time, effort, and costs through decentralized administration. These offerings include:
- IBM Tivoli zSecure Admin
- IBM Tivoli zSecure Visual
- IBM Tivoli zSecure CICS® Toolkit
Audit, monitoring and compliance components help ease the burden of compliance audits, improve security and incident handling, and increase overall operational effectiveness. Offerings include:
- IBM Tivoli zSecure Audit
- IBM Tivoli zSecure Alert
- IBM Tivoli zSecure Command Verifier
Tivoli zSecure v1.9 also includes:
- Currency with z/OS V1.9, including SMF Logger Stream Input and Digital Certificate enhancements
- Key reliability, availability, and serviceability (RAS) function, including error log integrity and data collection resiliency
Additional offerings include:
- IBM Tivoli Compliance Insight Manager Enabler for z/OS
The Tivoli zSecure suite allows you to submit mainframe security information into an enterprise
audit and compliance solution, through the seamless integration with IBM Tivoli Compliance Insight
Manager. Combining mainframe data with that from other operating systems, applications, and
databases, Tivoli Compliance Insight Manager provides the ability to capture comprehensive log data,
interpret that data through sophisticated log analysis and communicate results in an efficient,
streamlined manner for full enterprise-wide audit and compliance reporting. Tivoli Compliance
Insight Manager Enabler for z/OS provides the event source connection to supply the mainframe
information into the enterprise tool.
Back to top
|
|
| Key prerequisites |
For details, refer to the Software requirements section.
|
|
| Planned availability date |
December 14, 2007
Back to top
|
|
| Description |
Helps free administrators to focus on security
While preventing security breaches is paramount, administrators are frequently bogged down with tedious, time-consuming day-to-day tasks that divert their attention from security issues. The Tivoli zSecure suite offers a range of products designed to help reduce administration time, and enable valuable mainframe resources to focus on improving security quality.
Tivoli zSecure Admin is a leading security software program that enables efficient and effective IBM Resource Access Control Facility (RACF®) administration, typically using significantly less resources. By putting a user-friendly layer over your RACF databases, you can quickly enter and process administrative commands, generate custom reports, and clean up databases. And by implementing a repeatable process for security management, Tivoli zSecure Admin can help you reduce errors and improve the overall quality of services.
Tivoli zSecure Visual can reduce the need for expensive, RACF-trained expertise through a Microsoft® Windows®-based GUI for RACF administration. With the ability to establish a secure connection directly with RACF, Tivoli zSecure Visual is ideal for decentralizing RACF administration or enabling central security administration from outside Interactive System Productivity Facility/Time Sharing Option (ISPF/TSO). Tivoli zSecure CICS Toolkit allows you to perform mainframe administrative tasks from an IBM Customer Information Control System (CICS) environment, helping free scarce native RACF resources from basic administrative routines and enabling decentralized administration.
Track security events and prevent exposures to help ease compliance requirements
Over the past decade, the number of requirements with which organizations must comply has increased dramatically. Keeping up with the demands for audit and controls documentation, while also trying to prevent security breaches, can be overwhelming. The Tivoli zSecure suite delivers auditing, monitoring, and compliance solutions designed to help reduce security exposures.
Tivoli zSecure Audit delivers a mainframe compliance management and audit solution that enables you to quickly analyze and report on mainframe events, and automatically detect security exposures through extensive status auditing. The technology lets you create standard and customized reports, that can be generated in Extensible Markup Language (XML) format, and used in databases and reporting tools. Tivoli zSecure Audit also allows you to send Simple Network Management Protocol (SNMP) messages to an enterprise management console for policy exceptions or violations that indicate a security breach or weakness. This capability is provided for RACF and CA Top Secret environments.
Key RAS improvements are now included in zSecure v1.9, including error log integrity and data collection resiliency. These provide enhanced visibility into log information needed for debug activity.
Tivoli zSecure Alert offers a real-time mainframe threat monitoring solution that allows you to efficiently monitor intruders and identify misconfigurations that could hamper your compliance efforts. It goes beyond conventional intrusion detection solutions to support intrusion prevention by taking countermeasures via automatically generated commands. In addition, Tivoli zSecure Alert enables you to quickly determine unauthorized logons and attempts, user behavior that violates security policy, and when your core systems are at risk. With this information readily in hand, you can help identify misconfigurations before they can be exploited, while staying one step ahead of the auditors. This capability is provided for RACF and CA ACF2 environments.
Tivoli zSecure Command Verifier is a robust policy enforcement solution that can help enforce mainframe compliance to company policies by preventing erroneous commands. As a result, it helps increase control and decrease security risks and cleanup costs. Running in the background, Tivoli zSecure Command Verifier verifies RACF commands against your company's policies and procedures. When commands are entered, it verifies whether the commands comply with security policies and blocks or, optionally, adjusts the ones that do not comply.
To ensure currency with the latest releases of z/OS and RACF, Tivoli zSecure V1.9 includes support for SMF Logger Stream Input and Digital Certificate enhancements. zSecure uses SMF records extensively, and supports the streaming capability provided for SMF records, which can specify that different SMF record types can be written to separate log streams, and that the same SMF record type can be written to multiple log streams, providing flexibility in logging SMF data. Tivoli zSecure V1.9 also accepts and reports on the new command operands provided for the Digital Certificate enhancements in z/OS and RACF V1.9.
Tivoli Compliance Insight Manager Enabler for z/OS provides a link from zSecure Audit to the Tivoli Compliance Insight Manager tool, so that the mainframe audit information is included in the enterprise dashboard view.
Bringing it all together
The Tivoli zSecure suite is a valuable part of managing mainframe security as a process that helps meet the needs of regulators, auditors, and the business itself. These offerings are the result of a long-term commitment to innovation on the mainframe and to enabling you to improve and simplify mainframe security audit and administration. Through a broad range of offerings, the Tivoli zSecure suite helps you address your key mainframe challenges.
-
Audit and compliance:
- Report on questionable system options and dangerous settings of privileged users.
- Measure and verify the effectiveness of mainframe security and security policies.
-
User and security administration:
- Centrally manage and provision users, profiles, and resources.
- Constantly monitor crucial users and data for misuse.
-
Security risk detection and avoidance:
- Can reduce operational costs and achieve faster incident detection.
- Generate alerts with instant reports about RACF, IBM System Management Facilities (SMF), IBM z/OS, IBM DB2®, and the UNIX® subsystem.
Accessibility by people with disabilities
A U.S. Section 508 Voluntary Product Accessibility Template (VPAT) containing details on accessibility compliance can be requested at
Value Unit-based pricing
Value Unit pricing for eligible IBM System z IBM International Program License Agreement (IPLA) programs enables a lower cost of incremental growth and enterprise aggregation. Each System z IPLA product with Value Unit pricing, has a single price per Value Unit and a conversion matrix, called Value Unit Exhibit, for converting from some designated measurement to Value Units. Most commonly, Millions of Service Units (MSUs) is the measurement designated by IBM to be converted to Value Units. Some other measurements are engines or messages. Since MSUs are the most common measurement, that measurement will be used for the remainder of this description.
Value Unit pricing offers price benefits for you. For each System z IPLA program with Value Unit pricing, the quantity of that program needed to satisfy applicable IBM terms and conditions is referred to as the required license capacity . Each of the various Value Unit Exhibits stipulate that the larger your required license capacity, the fewer Value Units per MSU you will need. Value Unit Exhibits are uniquely identified by a three digit code and referred to using the nomenclature VUExxx, where xxx is the three digit code.
Subsequent acquisitions of Value Unit priced programs offer additional price benefits. The quantity of each System z IPLA program that you have acquired is referred to as entitled license capacity . If you wish to grow your entitled license capacity for a System z IPLA program, the calculation to determine additional needed Value Units is based upon the number of Value Units already acquired.
For each System z IPLA program with Value Unit pricing, you should:
- Determine the required license capacity, in MSUs
- Aggregate the MSUs across the enterprise
- Convert the total MSUs to Value Units, using the applicable Value Unit Exhibit
- Multiply the price per Value Unit by the total number of Value Units to determine the total cost
To simplify conversion from the designated measurement to Value Units or vice-versa, use the Value Unit Converter Tool. For additional information or to obtain a copy of the Value Unit Converter Tool, visit the Value Unit Converter Tool Web site
Note that Value Units of a given product cannot be exchanged, interchanged, or aggregated with Value Units of another product.
To determine the required license capacity for the System z IPLA program
you selected, refer to the
Terms and conditions
section.
Back to top
|
|
| Product positioning |
Positioning zSecure with Tivoli Compliance Insight Manager
Tivoli zSecure suite leverages the capabilities of Tivoli Compliance Insight Manager to enable inclusion of mainframe reporting on RACF, CA ACF2, and CA Top Secret into Tivoli Compliance Insight Manager enterprise-wide compliance dashboard and reporting, so that users can view the status of their enterprise security hub along with the rest of their environment. For more details, refer to Software Announcement 207-149 , dated July 3, 2007.
Positioning zSecure with Tivoli Security Operations Manager
Tivoli Security Operations Manager and zSecure Alert tools are companions to provide a comprehensive view of the mainframe threats and incidents.
Security Information and Event Management with Tivoli Security Operations Manager For information technology managers and information security managers who need to efficiently correlate, analyze, and respond to security events for intruders from perimeter and network devices in a real-time security operations dashboard, Tivoli Security Operations Manager offers a real-time Security Information and Event Management (SIEM) dashboard and reporting engine, with support for virtually all leading network and security devices, and hundreds of pre-defined correlation rules, enabling effective incident management.
Tivoli Security Operations Manager collects and analyzes information in real-time from security devices across the network. Through advanced correlation capabilities, it is able to identify and prioritize security incidents, and enables your organization to respond to these incidents automatically. Integration of Tivoli Security Operations Manager with zSecure Alert allows you to feed the security incident information from RACF into the Tivoli Security Operations Manager dashboard and reports.
Positioning zSecure with RACF
Your investment in RACF may be enhanced with the addition of zSecure, which provides integrated security audit and compliance monitoring and administration for z/OS and RACF.
Mainframe auditing For data center auditors, security managers, system programmers, and IT managers who need to monitor mainframe events and incidents, help reduce security vulnerabilities, and help enforce security policy compliance and generate audit reports, Tivoli zSecure suite offers a mainframe audit solution that provides analysis and reporting of mainframe events and automatic detection of exposures through extensive status auditing.
Mainframe security administration For RACF administrators and IT managers who need to simplify and automate routine administrative tasks, and decentralize administration control, Tivoli zSecure suite offers a mainframe administration suite that enables efficient and effective RACF administration, typically using less resources and providing richer functionality, and helping address compliance initiatives. And by implementing a repeatable process for security management, Tivoli zSecure suite can help you reduce errors and improve the overall quality of services.
Positioning zSecure with legacy Consul clients
Tivoli zSecure V1.9 suite offers additional functionality for existing Consul customers. Contact your IBM representative or Business Partner for more information on migrating to the latest zSecure version.
Business Partner information
If you are a Direct Reseller - System Reseller acquiring products from IBM, you may link directly to Business Partner information for this announcement. A PartnerWorld ID and password are required (use IBM ID).
BP Attachment for Announcement Letter 207-338
Trademarks
Back to top
|
|
| Education support |
Comprehensive education for IBM Tivoli® products is offered through Worldwide Tivoli Education Delivery Services. A wide range of training options are available, including classes led by instructors, learning on demand, on-site training, and blended learning solutions.
For additional information, visit
|
|
| Offering Information |
Product information is available via the Offering Information Web site
|
|
| Publications |
No publications are shipped with these programs.
The following English publications for IBM Tivoli zSecure V1.9 can be downloaded from the following Web site at general availability
Title Form number IBM Tivoli zSecure Audit for ACF2 Getting Started GI11-8183-01 Alert User Reference Manual SC23-6547-01 Visual Client Manual SC23-6548-01 Visual Server Manual SC23-6549-01 Command Verifier User's Guide SC23-6550-01 CICS(R) Toolkit User's Guide SC23-6551-01 IBM Tivoli zSecure Suite Admin and Audit for RACF(R) Getting Started GI11-8184-01 CARLa-Driven Components Installation and SC23-6556-01 Configuration Manual Quick Reference in A4 Fold Format Booklet SC23-6557-01 Quick Reference Booklet in Letter Fold Format SC23-6558-01 Quick Reference Booklet in Standard Format SC23-6559-01
The following English publications for Tivoli zSecure V1.9 are only available to licensed users and must be ordered from the IBM Publications Center. These publications cannot be downloaded from the Web.
IBM Tivoli zSecure Audit for ACF2 User Reference Manual LC23-6546-01 Admin User Reference Manual LC23-6552-01 Audit for RACF User Reference Manual LC23-6553-01 IBM Tivoli zSecure Suite Admin and Audit for RACF User Reference Manual LC23-6592-00 Admin and Audit User Reference Manual LC23-6555-01
All publications are available from the IBM Publications Center.
The Publications Center is a worldwide central repository for IBM product publications and marketing material with a catalog of 70,000 items. Extensive search facilities are provided. Payment options for orders are via credit card (in the U.S.) or customer number for 20 countries. A large number of publications are available online in various file formats, and they can all be downloaded by all countries, free of charge.
To order licensed publications from the IBM Publications Center, click
the customer support link, supply a valid IBM customer number, and
request the desired publications.
Back to top
|
|
| Technical information |
Specified operating environment
Hardware requirements
Minimum and recommended processor, disk space, and memory requirements for the IBM Tivoli zSecure V1.9 suite are:
Minimum Recommended
Processor z800 IBM System z9(TM)
or Enterprise Class (EC)
z9 Business Class (BC)
Disk space 300 MB 450 MB
Memory 1 GB 2 GB
Software requirements
The IBM Tivoli zSecure V1.9 suite is supported in the following environments:
- z/OS® V1R7
- z/OS V1R8
- z/OS V1R9
The zSecure products that include features for CA ACF2 and CA Top Secret support the following versions:
- CA ACF2 V8 and V9, and CA Top Secret V8 and V9
Limitations
For additional information, refer to Usage restrictions in the Terms and conditions section of this announcement, or to the license information document that is available on the IBM Software License Agreement Web site
Planning information
Packaging
IBM Tivoli zSecure products are distributed with:
- International Program License Agreement (Z125-3301)
- License Information document
- Tape
- Publications (refer to the Publications section)
This program, when downloaded from a Web site, contains the applicable IBM license agreement, and License Information, if appropriate, and will be presented for acceptance at the time of installation of the program. For future reference, the license and License Information will be stored in a directory such as LICENSE.TXT.
Security, auditability, and control
The IBM Tivoli zSecure suite uses the security and auditability features of the operating system software. The customer is responsible for evaluation, selection, and implementation of security features, administrative procedures, and appropriate controls in application systems and communication facilities.
Software Services
IBM Software Services has the breadth, depth, and reach to manage your services needs. You can leverage the deep technical skills of our lab-based, software services team and the business consulting, project management, and infrastructure expertise of our IBM Global Services team. Also, we extend our IBM Software Services reach through IBM Business Partners to provide an unmatched portfolio of capabilities. Together, we provide the global reach, intellectual capital, industry insight, and technology leadership to support any critical business need.
To learn more about IBM Software Services or to contact a Software Services sales specialist, visit
IBM Tivoli Enhanced Value-Based Pricing
IBM Tivoli software products are priced using IBM Tivoli Enhanced Value-Based Pricing. The Enhanced Value-Based Pricing system is based upon the IBM Tivoli Environment-Managed Licensing Model, which uses a managed-environment approach whereby price is determined by what is managed rather than the number and type of product components installed.
For example, all servers monitored with IBM Tivoli's monitoring product (IBM Tivoli Monitoring) require entitlements sufficient for those servers. Other Tivoli products may manage clients, client devices, agents, network nodes, users, or other items, and are licensed and priced accordingly.
Unlike typical systems management licensing models that require entitlements of specific software components to specific systems, the IBM Tivoli Environment-Managed Licensing Model provides the customer flexibility to deploy its IBM Tivoli software products within its environment in a manner that can address and respond to the customer's evolving architecture. That is, as the architecture of a customer's environment changes, the customer's implementation of IBM Tivoli software can be altered, as needed, without affecting the customer's license requirements (as long as the customer does not exceed its entitlements to the software).
Under Enhanced Value-Based Pricing, licensing and pricing of server-oriented applications are determined based upon the server's use in the customer's environment. Typically, such applications are licensed and priced in a manner that corresponds to each installed and activated processor of the server managed by the IBM Tivoli application to help correlate price to value while offering a simple solution.
Where a server is physically partitioned, this approach is modified. This partitioning technique is the approach used with systems that have either multiple cards or multiple frames, each of which can be configured independently. For servers capable of physical partitioning (for example, IBM System p Scalable POWERparallel Systems® servers, Sun Ultra servers, and HP Superdome servers), an entitlement is required for each processor in the physical partition being managed by the Tivoli application. For example, assume that a server has 24 processors installed in aggregate. If this server is not partitioned, entitlements are required for all 24 processors. If, however, it is physically partitioned into three partitions, each containing eight processors, and Tivoli products were managing only one of the three partitions, then entitlements would be required for the eight processors on the physical partition managed by the IBM Tivoli application.
For servers with virtual or logical partitions, entitlements are required for all installed and activated processors on the server. For each IBM Tivoli application managing a clustered environment, licensing is based on the cumulative number of installed and activated processors on each server in the cluster. Where the cluster includes physically partitioned servers, the considerations described above concerning physically partitioned servers apply as well.
Enhanced Value-Based Pricing recognizes the convergence of RISC and UNIX®, and Microsoft® Windows® and Intel® technologies, in order to simplify your licensing requirements, and to provide a smoother, more scalable model. Pricing and licensing does not differentiate between non-System z server platforms or operating systems. For some products, this platform neutrality extends to System z and other host servers as well.
IBM Tivoli Enhanced Value-Based Pricing terminology definitions
Authorized user
An authorized user is one and only one individual (named or unnamed) within or outside your enterprise. A Proof of Entitlement (PoE) must be obtained for each individual user accessing the program in any manner. A program licensed under an authorized user PoE may be installed on a single computer or server, and accessed by multiple users, provided that a PoE has been obtained for each individual user accessing the program either directly or indirectly (via a multiplexing program, device, or application server) through any means on behalf of the user.
Note that authorized users have unique specific identity and IDs cannot be shared. An ID can establish one or more connections and count as a single authorized user. Specific information to security products are:
An authorized user of IBM Tivoli Federated Identity Manager is any ID that accesses an application or service managed or protected by IBM Tivoli Federated Identity Manager.
An authorized user of IBM Tivoli Directory Integrator is one whose identity can be synchronized by IBM Tivoli Directory Integrator or that can access a connected system that can be synchronized by IBM Tivoli Directory Integrator.
An authorized user of IBM Tivoli Identity Manager is any ID whose identity is recorded in the Tivoli Identity Manager identity store.
An authorized user of IBM Tivoli Access Manager for e-business is any ID that accesses an application or service managed or protected by IBM Tivoli Access Manager for e-business.
Client device or client
A client device is a computing device that requests the execution of a set of commands, procedures, or applications from another computer system that is typically referred to as a server. Multiple client devices may share access to a common server. A client device generally has some processing capability or is programmable to allow a user to do work. Examples include, but are not limited to, notebook computers, desktop computers, desk side computers, technical workstations, appliances, automated teller machines, point-of-sale terminals, tills and cash registers, and kiosks.
Engine
An engine is also referred to as a central processor (CP) or processor. Engines for traditional workloads are called General Purpose CPs. Engines for Linux workloads are called Integrated Facility for Linux (IFL) engines or Linux-only engines. Engines for Coupling Facility workloads are called Integrated Coupling Facility (ICF) engines.
Enterprise
An enterprise is a person or single entity and those subsidiaries with more than 50% ownership.
External user
An external user is an authorized user who is not part of the enterprise.
IBM IFL
This optional facility enables additional processing capacity exclusively for Linux workload, with no effect on the model designation of a System z or OS/390® server. Consequently, executing Linux workload on the IFL will not, in most cases, result in any increased IBM software charges for z/OS, OS/390, VM, VSE, or TPF operating systems and applications. There is, as indicated, a charge associated with the IFL, and there may also be a charge for applications which run on the IFL.
The IFL may be dedicated to a single Linux-mode logical partition or it may be shared by multiple Linux-mode logical partitions. Installations should note that the Linux workspace enabled by this facility will not support any of the traditional S/390 operating systems (OS/390, TPF, VSE, or VM). Only Linux applications or Linux operating in conjunction with the Virtual Image Facility, an environment that operates within a logical partition or in native S/390® mode and provides the capability to create multiple Linux images, are supported by IBM S/390 IFL.
IBM Tivoli Directory Integrator connected system
A connected system is any directory, database, application, or file integrated or merged by IBM Tivoli Directory Integrator.
IBM Tivoli Storage Manager HSM for Windows terabyte (TB) capacity
IBM Tivoli Storage Manager HSM for Windows includes primary HSM disk storage pool size combined with the amount of utilized HSM removable media storage pool. Storage pools are configured on the IBM Tivoli Storage Manager server.
IBM System Storage Archive Manager TB capacity
IBM System Storage Archive Manager includes primary disk storage pool size combined with the amount of utilized primary removable media storage used by the IBM System Storage Archive Manager server.
Capacity does not include:
Copy storage pools for the space-managed data that reside on disk.
Copy storage pools for the space-managed data that reside on removable media.
Space used on the IBM Tivoli Storage Manager server for any purpose other than the primary storage of space-managed data.
Disk on the host being space managed.
A virtual tape library (VTL) is considered a removable media device, so capacity is based on utilization.
The minimum amount of capacity that can be purchased is 1 TB.
Partial capacity will be rounded up to the next whole number of TBs.
Additional capacity must be added in increments of 1 TB.
IBM TotalStorage® Productivity Center TB capacity
A TB capacity is each individual TB of storage capacity managed by the IBM TotalStorage Productivity Center products. Managed capacity for the IBM TotalStorage Productivity Center for Replication and IBM TotalStorage Productivity Center for Replication Two Site BC is defined as the source device capacity. Only the source device capacity is included in this pricing definition (not the target device).
Managed processor (charging under full capacity in the managed environment)
Charges are based on the active processors on the machines in the computing environment affiliated with the program rather than on the server where the program is run. The managed processors which require PoEs are defined in the License Information's program-unique terms.
Notes:
- IBM defines a physical processor in a computer as a functional unit that interprets and executes instructions. A physical processor consists of at least an instruction control unit and one or more arithmetic and logic units.
- Multicore technology allows two or more processors (commonly called cores) to be active on a single silicon chip. With multicore technology, IBM considers each core to be a physical processor. For example, in a dual-core chip, there are two physical processors residing on the single silicon chip.
- The program may not run on some or all of the processors for which PoEs are required by the program's valuation method.
- In the System z IFL environment, each IFL engine is considered a single physical processor.
- Threading, a technique which makes a single processor seem to perform as two or more, does not affect the count of physical processors.
- Where blade technology is employed, each blade is considered a separate server and charging is based upon the total number of processors on the blades with which the program is affiliated.
- Not all processors require the same number of Value Unit entitlements. To determine the number of Value Unit entitlements required, refer to the processor Value Unit conversion table on the Passport Advantage® Web site
Millions of Service Units (MSUs)
MSUs is defined as Millions of Service Units (MSUs) per hour. Units of workload capacity of an eligible machine. The number of MSUs per machine type/model is published by IBM and can be viewed online at
For more detailed information about System z software pricing, go to
Network node or node
Network nodes include routers, switches, hubs, and bridges that contain a network management agent. A single network node may contain any number of interfaces or ports.
Partitions
A server's resources (CPU, memory, I/O, interconnects, and buses) may be divided according to the needs of the applications running on the server. This partitioning can be implemented with physical boundaries (Physical Partitions) or logical boundaries (Logical Partitions).
Physical Partitions are defined by a collection of processors dedicated to a workload and can be used with systems that have either multiple cards or multiple frames, each of which can be configured independently. In this method, the partitions are divided along hardware boundaries and processors, and the I/O boards, memory, and interconnects are not shared.
Logical Partitions are defined by software rather than hardware and allocate a pool of processing resources to a collection of workloads. These partitions, while separated by software boundaries, share hardware components and run in one or more physical partitions.
Port
A port is the physical connection between a device and the network.
Processor (per processor charging under full capacity)
In full capacity charging, PoE must be acquired for all activated processors (available for use) that are on the server where the program or a component of the program is run.
Notes:
- IBM defines a physical processor in a computer as a functional unit that interprets and executes instructions. A physical processor consists of at least an instruction control unit and one or more arithmetic and logic units.
- Multicore technology allows two or more processors (commonly called cores) to be active on a single silicon chip. With multicore technology, IBM considers each core to be a physical processor. For example, in a dual-core chip, there are two physical processors residing on the single silicon chip.
- In the System z IFL environment, each IFL engine is considered a single physical processor.
- Threading, a technique which makes a single processor seem to perform as two or more, does not affect the count of physical processors.
- Where blade technology is employed, each blade is considered a separate server and charging is based upon the total number of processors on the blade on which the program is run.
- When a server is shipped with six processors, but two of them are inactive, four processors are active for the customer.
- Not all processors require the same number of Value Unit entitlements. To determine the number of Value Unit entitlements required, refer to the processor value unit conversion table on the Passport Advantage Web Site
Server
A server is a computer system that executes requested procedures, commands, or applications to one or more user or client devices over a network. A PoE must be obtained for each server on which the program or a component of the program is run or for each server managed by the program. Where blade technology is employed, each blade is considered a separate server.
Standby or backup systems
For programs running or resident on backup machines, IBM defines three types of situations: cold, warm and hot. In cold and warm situations, a separate entitlement for the copy on the backup machine is normally not required and typically no additional charge applies. In a hot backup situation, the customer needs to acquire other license or entitlements sufficient for that server. All programs running in backup mode must be solely under the customer's control, even if running at another enterprise's location.
As a practice, the following are definitions and allowable actions concerning the copy of the program used for backup purposes.
Cold: A copy of the program may reside, for backup purposes, on a machine as long as the program is not started. There is no additional charge for this copy.
Warm: A copy of the program may reside for backup purposes on a machine and is started, but is idling, and is not doing any work of any kind. There is no additional charge for this copy.
Hot: A copy of the program may reside for backup purposes on a machine, is started, and is doing work. The customer must acquire a license or entitlements for this copy and there will generally be an additional charge.
Doing work includes, for example, production, development, program maintenance, and testing. It also could include other activities such as mirroring of transactions, updating of files, synchronization of programs, data or other resources (for example, active linking with another machine, program, database or other resource, and so on), or any activity or configurations that would allow an active hot switch or other synchronized switch over between programs, databases, or other resources to occur.
In the case of a program or system configuration that is designed to support a high availability environment by using various techniques (for example, duplexing, mirroring of files, or transactions, maintaining a heartbeat, active linking with another machine, program, database, or other resource), the program is considered to be doing work in the hot situation and a license or entitlement must be purchased.
Terabyte (T/TB)
1 terabyte of managed storage = 2 to the power of 40 bytes = 1,099,511,627,776 bytes, trillion bytes.
Tivoli Management Points
A Tivoli Management Point is a metric used to compute license quantities and is program specific.
Value Units
A Value Unit is a pricing charge metric for program license entitlements, which is based upon the quantity of a specific designated measurement used for a given program. Each program has a designated measurement. The most commonly used designated measurements are processor cores and MSUs. However, for select programs, there are other designated measurements such as servers, users, client devices, and messages. The number of Value Unit entitlements required for your specific implementation of the given program must be obtained from a conversion table associated with the program. You must obtain a PoE for the appropriate number of Value Unit entitlements for your implementation. The Value Unit entitlements of a given program cannot be exchanged, interchanged, or aggregated with Value Unit entitlements of another program. Whenever the designated measurement is a processor core, not all processors require the same number of Value Unit entitlements. To determine the number of Value Unit entitlements required, refer to the processor Value Unit conversion table on the Passport Advantage Web site.
Product and licensing Web sites
A complete list of IBM Tivoli products is available at
IBM Tivoli product licensing documents are available at
System z software pricing examples (MSU based)
The pricing example below should be used to determine required license entitlements for the following software products for System z:
Value Unit
Product Exhibit (VUE)
IBM Tivoli Compliance Insight VUE020
Manager Enable for z/OS
IBM Tivoli zSecure Admin VUE020
IBM Tivoli zSecure Alert VUE020
IBM Tivoli zSecure Audit VUE020
IBM Tivoli zSecure CICS Toolkit VUE020
IBM Tivoli zSecure Command Verifier VUE020
IBM Tivoli zSecure Visual VUE020
System z server
1,000 MSU System z server with 25 engines
All products for this example listed above employ Value Unit slope Value Unit Exhibit 020 (VUE020). Translation from MSUs to Value Units:
VUE020
Value
MSUs Units/MSU
Base 1-3 1.00
Tier A 4-45 .15
Tier B 46-175 .08
Tier C 176-315 .04
Tier D 316+ .03
If the customer has installed 1,000 MSUs, the applicable number of Value Units will be:
Value Value
Level MSUs Units/MSU Units
Base 3 1.00 3.00
Tier A 42 0.15 6.30
Tier B 130 0.08 10.40
Tier C 140 0.04 5.60
Tier D 685 0.03 20.55
Total 1,000 45.85
When calculating the total number of Value Units, the sum is rounded up to the next integer. In this example, the customer will need to license 46 Value Units.
Note:
IBM RACF for z/OS (a separate IBM MLC offering) or a comparable competitive offering (CA ACF2 or CA Top Secret) is a prerequisite for the IBM Tivoli zSecure suite. For more information on RACF, refer to
Scenario 1: MSU-based pricing
Transaction 1
Enterprise ABC initially wants to work with the following system configuration:
On one System z server with 1,000 MSUs, they want to run IBM Tivoli zSecure Audit and zSecure Alert. The same calculation applies to both Audit and Alert components:
Value Value
Level MSUs Units/MSU Units
Base 3 1.00 3.00
Tier A 42 0.15 6.30
Tier B 130 0.08 10.40
Tier C 140 0.04 5.60
Tier D 685 0.03 20.55
Total 1,000 45.85
The customer must purchase 46 Value Units for Audit and 46 Value Units for Alert.
Transaction 2
After the initial purchase, enterprise ABC wants to expand their use of the zSecure suite to include the IBM Tivoli zSecure Command Verifier, Admin, Visual, and CICS Toolkit, along with the IBM Tivoli Compliance Insight Manager Enabler for z/OS. IBM Tivoli Compliance Insight Manager is sold separately through distributed pricing structures. Refer to the separate software announcement and pricing example for Tivoli Compliance Insight Manager.
The same calculation applies to each of these components:
Value Value
Level MSUs Units/MSU Units
Base 3 1.00 3.00
Tier A 42 0.15 6.30
Tier B 130 0.08 10.40
Tier C 140 0.04 5.60
Tier D 685 0.03 20.55
Total 1,000 45.85
The customer must purchase 46 Value Units for each of Command Verifier,
Admin, Visual, CICS Toolkit, and Tivoli Compliance Insight Manager
Enabler.
Back to top
|
|
| Ordering information |
Ordering z/OS through the Internet
ShopzSeries provides an easy way to plan and order your z/OS ServerPac or CBPDO. It will analyze your current installation, determine the correct product migration, and present your new configuration based on z/OS. Additional products can also be added to your order (including determination of whether all product requisites are satisfied). ShopzSeries is available in the U.S. and several countries in Europe. In countries where ShopzSeries is not available yet, contact your IBM representative (or IBM Business Partner) to handle your order via the traditional IBM ordering process. For more details and availability, visit the ShopzSeries Web site at
The products in this announcement have one charge unit Value Units.
Translation from MSUs to Value Units example using VUE001
Value
MSUs Units/MSU
Base 1-3 5.25
Tier A 4-45 .83
Tier B 46-175 .35
Tier C 176-315 .26
Tier D 316+ .20
Note: For the actual translation from MSUs to Value Units for this product, refer to the table that follows.
Ordering example:
The total number of Value Units is calculated according to the following example.
If the customer has installed 1,000 MSUs, the applicable Value Units would be:
Translation from MSUs to Value Units (VUE001)
MSUs * Value Units/MSU = Value Units
Base 3 * 5.25 = 15.75
Tier A 42 * .83 = 34.86
Tier B 130 * .35 = 45.50
Tier C 140 * .26 = 36.40
Tier D 685 * .20 = 137.00
Total 1,000 270
When calculating the total number of Value Units, the sum is to be rounded up to the next integer.
Value Units for non-MSU-based S/390 processors using VUE001:
MP3000 models H30 = 21.00 Value Units per machine H50 = 22.00 Value Units per machine H70 = 26.00 Value Units per machine ESL models = 9.00 Value Units per machine
Basic license
Single version charging: To elect single version charging, you must notify and identify to IBM the prior program and replacement program, and the machine the programs are operating on.
Current licensees
Current licensees, with support in effect, will receive instructions on how to order this update.
Current licensees of IBM Tivoli zSecure V1.8.1 must place a new order to obtain the new IBM Tivoli zSecure V1.9 distribution medium.
New licensees
Orders for new licenses will be accepted now.
Shipment will begin on the planned availability date.
Basic license
This table should be used for all zSecure PIDs.
Value
VUE020 MSUs Units/MSU
Base 1-3 1.00
Tier A 4-45 0.15
Tier B 46-175 0.08
Tier C 176-315 0.04
Tier D 316+ 0.03
To order, specify the program product number and the appropriate license or charge option. Also, specify the desired distribution medium. To suppress shipment of media, select the license-only option in CFSW.
Program name: IBM Tivoli zSecure Admin
Program PID: 5655-T01
Entitlement License option/ identifier Description Pricing metric S01471B zSecure Admin Basic OTC, per Value Unit
Orderable supply ID Language Distribution medium S01472B English 3480 tape cartridge
Subscription and Support PID: 5655-T03
Entitlement License option/
identifier Description Pricing metric
S01471M zSecure Admin S&S Basic ALC, per Value Unit SW S&S
no charge, decline SW S&S
per MSU SW S&S registration
Orderable supply ID Language Distribution medium S01472L English Hardcopy publication
Ordering information for On/Off Capacity on Demand (CoD)
IBM Tivoli zSecure Admin is eligible for On/Off CoD with a temporary use charge calculated based on MSUs per-day usage.
Program name: IBM zSecure Admin
Program PID: 5655-T01
Entitlement License option/ identifier Description Pricing metric S01471B zSecure Admin Basic OTC, per MSU-day TUC
Program name: IBM Tivoli zSecure Audit
Program PID: 5655-T02
Entitlement License option/
identifier Description Pricing metric
Basic OTC, per Value Unit
S01471C RACF
S01471D ACF2
S01471F Top Secret
Orderable
supply ID Language Distribution medium
English 3480 tape cartridge
S01472G RACF
S01472J ACF2
S014745 Top Secret
Subscription and Support PID: 5655-T04
Entitlement License option/
identifier Description Pricing metric
Basic ALC, per Value Unit SW S&S
no charge, decline SW S&S
per MSU SW S&S registration
S01471N RACF S&S
S01471P ACF2 S&S
S01471R Top Secret S&S
Orderable
supply ID Language/Description Distribution medium
English Hardcopy publication
S01472N RACF
S01480L ACF2
S01474H Top Secret
Ordering information for On/Off CoD
IBM Tivoli zSecure Audit is eligible for On/Off CoD with a temporary use charge calculated based on MSUs per-day usage.
Program name: IBM zSecure Audit
Program PID: 5655-T02
Entitlement License option/
identifier Description Pricing metric
Basic OTC, per MSU-day TUC
S01471C RACF
S01471D ACF2
S01471F Top Secret
Program name: IBM Tivoli zSecure CICS Toolkit
Program PID: 5655-T05
Entitlement License option/ identifier Description Pricing metric S01471S zSecure CICS Toolkit Basic OTC, per Value Unit
Orderable supply ID Language Distribution medium S01472R English 3480 tape cartridge
Subscription and Support PID: 5655-T06
Entitlement License option/
identifier Description Pricing metric
S01472T zSecure CICS Toolkit Basic ALC, per Value Unit SW S&S
S&S no charge, decline SW S&S
per MSU SW S&S registration
Orderable supply ID Language Distribution medium S01472V English Hardcopy publication
Ordering information for On/Off CoD
IBM Tivoli zSecure CICS Toolkit is eligible for On/Off CoD with a temporary use charge calculated based on MSUs per-day usage.
Program name: IBM Tivoli zSecure CICS Toolkit
Program PID: 5655-T05
Entitlement License option/
identifier Description Pricing metric
S01471S zSecure CICS Basic OTC, per MSU-day TUC
Toolkit
Program name: IBM Tivoli zSecure Command Verifier
Program PID: 5655-T07
Entitlement License option/ identifier Description Pricing metric S01471T zSecure Command Verifier Basic OTC, per Value Unit
Orderable supply ID Language Distribution medium S01472X English 3480 tape cartridge
Subscription and Support PID: 5655-T08
Entitlement License option/
identifier Description Pricing metric
S01471V zSecure Command Basic ALC, per Value Unit SW S&S
Verifier no charge, decline SW S&S
per MSU SW S&S registration
Orderable supply ID Language Distribution medium S014730 English Hardcopy publication
Ordering information for On/Off CoD
IBM Tivoli zSecure Command Verifier is eligible for On/Off CoD with a temporary use charge calculated based on MSUs per-day usage.
Program name: IBM zSecure Command Verifier
Program PID: 5655-T07
Entitlement License option/
identifier Description Pricing metric
S01471T zSecure Command Basic OTC, per MSU-day TUC
Verifier
Program name: IBM Tivoli zSecure Visual
Program PID: 5655-T09
Entitlement License option/ identifier Description Pricing metric S01471X zSecure Visual Basic OTC, per Value Unit
Orderable supply ID Language Distribution medium S01471Z English 3480 tape cartridge
Subscription and Support PID: 5655-T10
Entitlement License option/
identifier Description Pricing metric
S014721 zSecure Visual S&S Basic ALC, per Value Unit SW S&S
no charge, decline SW S&S
per MSU SW S&S registration
Orderable supply ID Language Distribution medium S014722 English Hardcopy publication
Ordering information for On/Off CoD
IBM Tivoli zSecure Visual is eligible for On/Off CoD with a temporary use charge calculated based on MSUs per-day usage.
Program name: IBM Tivoli zSecure Visual
Program PID: 5655-T09
Entitlement License option/ identifier Description Pricing metric S01471X zSecure Visual Basic OTC, per MSU-day TUC
Program name: IBM Tivoli zSecure Alert
Program PID: 5655-T11
Entitlement License option/
identifier Description Pricing metric
Basic OTC, per Value Unit
S014725 RACF
S014728 ACF2
Orderable
supply ID Language Distribution medium
English 3480 tape cartridge
S014727 RACF
S014743 ACF2
Subscription and Support PID: 5655-T12
Entitlement License option/
identifier Description Pricing metric
Basic ALC, per Value Unit SW S&S
no charge, decline SW S&S
per MSU SW S&S registration
S014733 RACF S&S
S014736 ACF2 S&S
Orderable
supply ID Language Distribution medium
English Hardcopy publication
S014735 RACF
S014747 ACF2
Ordering information for On/Off CoD
IBM Tivoli zSecure Alert is eligible for On/Off CoD with a temporary use charge calculated based on MSUs per-day usage.
Program name: IBM Tivoli zSecure Alert
Program PID: 5655-T11
Entitlement License option/
identifier Description Pricing metric
Basic OTC, per MSU-day TUC
S014725 RACF
S014728 ACF2
Program name: IBM Tivoli Compliance Insight Manager Enabler for z/OS
Program PID: 5655-T15
Entitlement License option/
identifier Description Pricing metric
Basic OTC, per Value Unit
S01473W RACF
S014748 ACF2
S014749 Top Secret
S01474K DB2(R)
Orderable
supply ID Language/Description Distribution medium
English 3480 tape cartridge
S01473X RACF
S014740 ACF2
S01474V Top Secret
S01474T DB2
Subscription and Support PID: 5655-T16
Entitlement License option/
identifier Description Pricing metric
Basic ALC, per Value Unit SW S&S
no charge, decline SW S&S
per MSU SW S&S registration
S01473K RACF S&S
S01474B ACF2 S&S
S01474C Top Secret S&S
S01474W DB2 S&S
Orderable
supply ID Language/Description Distribution medium
English Hardcopy publication
S01474R RACF
S01474P ACF2
S01474N Top Secret
S01474M DB2
Ordering information for On/Off CoD
IBM Tivoli Compliance Insight Manager Enabler for z/OS is eligible for On/Off CoD with a temporary use charge calculated based on MSUs per-day usage.
Program name: IBM Tivoli Compliance Insight Manger Enabler for z/OS
Program PID: 5655-T15
Entitlement License option/
identifier Description Pricing metric
Basic OTC, per MSU-day TUC
S01473W RACF
S014748 ACF2
S014749 Top Secret
S01474K DB2
Subscription and Support
Subscription and Support must be ordered to receive voice technical support via telephone during normal business hours, and future releases and versions, at no additional charge. The capacity of Subscription and Support (for example, Value Units or number of processors) must be the same as the capacity ordered for the product licenses.
To order, specify the Subscription and Support program product number and the appropriate license or charge option.
IBM is also providing Subscription and Support for these products, via a separately purchased offering, under the terms of the IBM International Agreement for Acquisition of Support Maintenance. This offering:
- Includes and extends the support services provided in the base support to include technical support via telephone during normal business hours.
- Entitles customers to future releases and versions, at no additional charge. Note that the customer is not entitled to new products.
When Subscription and Support is ordered, the charges will automatically renew annually unless cancelled by the customer.
Basic machine-readable material
Customization option for z/OS: Select the following feature number to customize your order if running on the z/OS platform. This feature can be specified on the initial or MES orders.
Feature number Description 3450 Satellite Electronic Delivery
Customized Offerings
Product deliverables are shipped only via Customized Offerings (for example, CBPDO, ServerPac, SystemPac®). CBPDO and ServerPac are offered for Internet delivery, where ShopzSeries product ordering is available. Internet delivery of ServerPac may help improve automation and software delivery time. For more details on Internet delivery, refer to the ShopzSeries help information at
Media type for this software product is chosen during the Customized Offerings ordering process. Based on your customer environment, it is recommended that the highest possible density tape media is selected. Currently offered media types are:
- CBPDOs 3480, 3480 Compressed, 3490E, 3590, 3592*
- ServerPacs 3480, 3480 Compressed, 3490E, 3590, 3592*
- SystemPacs 3480, 3480 Compressed, 3490E, 3590, 3592*
- *
- 3592 is highest density media. Selecting 3592 will ship the fewest number of media.
Once a product becomes generally available, it will be included in the next ServerPac and SystemPac monthly update.
Production of software product orders will begin on the planned general availability date.
- CBPDO shipments will begin one week after general availability.
- ServerPac shipments will begin two weeks after inclusion in ServerPac.
- SystemPac shipments will begin four weeks after inclusion in SystemPac due to additional customization, and data input verification.
|
|
| Terms and conditions |
The information provided in this announcement letter is for reference and convenience purposes only. The terms and conditions that govern any transaction with IBM are contained in the applicable contract documents such as the IBM International Program License Agreement, IBM International Passport Advantage Agreement, and the IBM Agreement for Acquisition of Software Maintenance.
Licensing: IBM International Program License Agreement including the License Information document and PoE govern your use of the program. PoEs are required for all authorized use.
Agreement for Acquisition of Software Maintenance
The following agreement applies for maintenance and does not require customer signatures:
- IBM Agreement for Acquisition of Software Maintenance (Z125-6011)
These programs are licensed under the IBM Program License Agreement (IPLA) and the associated Agreement for Acquisition of Software Maintenance, which provides for support with ongoing access to releases and versions of the program. IBM includes one year of Software Maintenance with the initial license acquisition of each program acquired. The initial period of Software Maintenance can be extended by the purchase of a renewal option, if available. These programs have a one-time license charge for use of the program and an annual renewable charge for the enhanced support that includes telephone assistance (voice support for defects during normal business hours), as well as access to updates, releases, and versions of the program as long as support is in effect.
S/390 and System z IBM Operational Support Services SoftwareXcel is an option if you desire added services.
Limited warranty applies: Yes
Money-back guarantee: If for any reason you are dissatisfied with the program and you are the original licensee, you may obtain a refund of the amount you paid for it, if within 30 days of your invoice date you return the program and its PoE to the party from whom you obtained it. If you downloaded the program, you may contact the party from whom you acquired it for instructions on how to obtain the refund.
For clarification, note that for programs acquired under any of the IBM On/Off CoD software offerings, this term does not apply since these offerings apply to programs already acquired and in use by you.
Authorization for use on home/portable computer: You may not copy and use this program on another computer without paying additional license fees.
Volume orders (IVO): No
IBM International Passport Advantage Agreement
Passport Advantage applies: No
Usage restriction: Yes
Usage is limited to the quantity of Value Units licensed.
For additional information, refer to the License Information document that is available on the IBM Software License Agreement Web site
Software Maintenance applies
No. For operating system software, the revised IBM Operational Support Services SoftwareXcel offering will provide support for those operating systems and associated products that are not available with the newly announced Software Maintenance offering.
This will ensure total support coverage for your enterprise needs, including IBM and selected non-IBM products. For complete lists of products supported under both the current and revised SoftwareXcel offering, visit
For additional information on the revised IBM Operational Support Services, refer to Services Announcement 601-023 , dated July 10, 2001.
System i Software Maintenance applies: No
Variable charges apply: Yes
Educational allowance available
Yes. A 15% education allowance applies to qualified education institution customers.
Sub-capacity terms and conditions
For each System z IPLA program with Value Unit pricing, the quantity of that program needed to satisfy applicable IBM terms and conditions is referred to as the required license capacity. Your required license capacity is based upon the following factors:
- The System z IPLA program you select
- The applicable Value Unit Exhibit
- The applicable terms
- Whether your current mainframes are full capacity or sub-capacity
For more information on the Value Unit Exhibit for the System z IPLA program you selected, refer to the Ordering information information section.
Program number Program name Terms 5655-T01 IBM Tivoli zSecure Admin z/OS based 5655-T03 IBM Tivoli zSecure Admin z/OS based 5655-T02 IBM Tivoli zSecure Audit z/OS based 5655-T04 IBM Tivoli zSecure Audit z/OS based 5655-T07 IBM Tivoli zSecure Command Verifier z/OS based 5655-T08 IBM Tivoli zSecure Command Verifier z/OS based 5655-T09 IBM Tivoli zSecure Visual z/OS based 5655-T10 IBM Tivoli zSecure Visual z/OS based 5655-T05 IBM Tivoli zSecure CICS Toolkit Execution based 5655-T06 IBM Tivoli zSecure CICS Toolkit Execution based 5655-T11 IBM Tivoli zSecure Alert Execution based 5655-T12 IBM Tivoli zSecure Alert Execution based
Full-capacity mainframes: In cases where full capacity is applicable, the following terms apply.
Execution based, z/OS based, full-machine based: The required capacity of a System z IPLA program with these terms equals the MSU-rated capacity of the machines where the System z IPLA program executes.
For more information on mainframe MSU-rated capacities, visit
Reference based: The required license capacity of a System z IPLA program with these terms equals the license capacity of the applicable monthly license charge (MLC) program. This MLC program is called the parent program.
Sub-capacity mainframes: In cases where sub-capacity is applicable, the following terms apply.
Execution based: The required capacity of a System z IPLA sub-capacity program with these terms equals the capacity of the LPARs where the System z IPLA program executes.
z/OS based: The required license capacity of a System z IPLA program with these terms equals the license capacity of z/OS (and z/OS.e) on the machines where the System z IPLA program executes.
Reference based: The required license capacity of a System z IPLA program with these terms equals the license capacity of the applicable monthly license charge (MLC) program. This MLC program is called the parent program.
Full-machine based: The required license capacity of a System z IPLA program with full-machine-based terms equals the MSU-rated capacity of the machines where the System z IPLA program executes.
For more information on mainframe MSU-rated capacities, refer to The System/370, System/390®, and System z Machine Exhibit (Z125-3901), or visit the Mainframes section of the System z Exhibits Web site
For more information on sub-capacity System z IPLA terms and conditions, refer to Software Announcement 204-184 , dated August 10, 2004.
For additional information for products with reference-based terms, System z IPLA sub-capacity programs with reference-based terms adds value to the parent program across the environment, regardless of where in the environment the System z IPLA program executes.
An environment is defined as either a single or stand-alone machine or a qualified Parallel Sysplex®. You may have one or more different environments across the enterprise. To determine the required license capacity for each System z IPLA program with referenced-based terms, each environment should be assessed separately.
When a System z IPLA sub-capacity program with reference-based terms is used in a qualified Parallel Sysplex environment, the required license capacity of the System z IPLA program must equal with the license capacity of the parent program across the Parallel Sysplex. Qualified Parallel Sysplex refers to one:
- That meets the criteria defined in Hardware Announcement 198-001 , dated January 13, 1998
- Where MLC pricing is aggregated across the Sysplex
Sub-capacity eligibility: To be eligible for sub-capacity charging on select System z IPLA programs, you must first implement and comply with all terms of either sub-capacity Workload License Charges (WLC) or sub-capacity Entry Workload License Charges (EWLC). To implement sub-capacity WLC or EWLC, a machine must be System z (or equivalent). On that machine:
- All instances of the OS/390 operating system must be migrated to the z/OS (or z/OS.e) operating systems
- Any licenses for the OS/390 operating system must be discontinued
- All instances of the z/OS operating (or z/OS.e) systems must be running in z/Architecture (64-bit) mode
For that machine, you must create and submit a Sub-Capacity Report to IBM each month. Sub-Capacity Reports must be generated using the Sub-Capacity Reporting Tool (SCRT). For additional information or to obtain a copy of SCRT, visit the System z Software Pricing Web site
You must comply with all of the terms of the WLC or EWLC offering, whichever is applicable:
- The complete terms and conditions of sub-capacity WLC are defined in the IBM Customer Agreement Attachment for System z Workload License Charges (Z125-6516).
- The complete terms and conditions for sub-capacity EWLC are defined in the IBM Customer Agreement Attachment for IBM eServer System z 890 and 800 License Charges (Z125-6587).
Additionally, you must sign and comply with the terms and conditions specified in the amendment to the IPLA contract Amendment for IBM System z9 and eServer zSeries Programs Sub-Capacity Pricing (Z125-6929). Once the amendment is signed, the terms in the amendment replace any and all previous System z IPLA sub-capacity terms and conditions.
Sub-capacity utilization determination
Sub-capacity utilization is determined based on the utilization of an eligible operating system and machine (for example, z/OS running in z/Architecture (64 bit) mode on a System z (or equivalent) server).
Sub-capacity utilization is determined based on the product's own execution as reported to IBM in accordance with the requirements for reporting sub-capacity utilization for products.
On/Off CoD
To be eligible for On/Off CoD pricing, you must be enabled for temporary capacity on the
corresponding hardware, and the required contract, Attachment for Customer Initiated Upgrade and IBM
eServer On/Off Capacity on Demand Software (Z125-6611) must be signed prior to use.
Back to top
|
|
| Prices |
Information on charges is available at Web site
In the Electronic tools category, select the option for Purchase/upgrade tools.
Pricing for 5698-xxx MSU-based System z offerings
Program name: IBM Tivoli zSecure Admin
Program PID: 5655-T01
Entitlement License option/
identifier Description Pricing metric
S01471B zSecure Admin Basic OTC, per Value Unit
Basic OTC, per MSU-day TUC
Subscription and Support PID: 5655-T03
Entitlement License option/
identifier Description Pricing metric
S01471M zSecure Admin Basic ALC, per Value Unit SW S&S
No charge, decline SW S&S
Per MSU SW S&S registration
Program name: IBM Tivoli zSecure Audit
Program PID: 5655-T02
Entitlement License option/
identifier Description Pricing metric
Basic OTC, per Value Unit
Basic OTC, per MSU-day TUC
S01471C zSecure Audit RACF
S01471D zSecure Audit ACF2
S01471F zSecure Audit Top Secret
Subscription and Support PID: 5655-T04
Entitlement License option/
identifier Description Pricing metric
Basic ALC, per Value Unit SW S&S
No charge, decline SW S&S
Per MSU SW S&S registration
S01471N zSecure Audit -- RACF
S&S
S01471P zSecure Audit -- ACF2
S&S
S01471R zSecure Audit -- Top
Secret S&S
Program name: IBM Tivoli zSecure CICS Toolkit
Program PID: 5655-T05
Entitlement License option/
identifier Description Pricing metric
S01471S zSecure CICS Toolkit Basic OTC, per Value Unit
Basic OTC, per MSU-day TUC
Subscription and Support PID: 5655-T06
Entitlement License option/
identifier Description Pricing metric
S01472T zSecure CICS Toolkit Basic ALC, per Value Unit SW S&S
No charge, decline SW S&S
Per MSU SW S&S registration
Program name: IBM Tivoli zSecure Command Verifier
Program PID: 5655-T07
Entitlement License option/
identifier Description Pricing metric
S01471T zSecure Command Verifier Basic OTC, per Value Unit
Basic OTC, per MSU-day TUC
Subscription and Support PID: 5655-T08
Entitlement License option/
identifier Description Pricing metric
S01471V zSecure Command Basic ALC, per Value Unit SW S&S
Verifier No charge, decline SW S&S
Per MSU SW S&S registration
Program name: IBM Tivoli zSecure Visual
Program PID: 5655-T09
Entitlement License option/
identifier Description Pricing metric
S01471X zSecure Visual Basic OTC, per Value Unit
Basic OTC, per MSU-day TUC
Subscription and Support PID: 5655-T10
Entitlement License option/
identifier Description Pricing metric
S014721 zSecure Visual Basic ALC, per Value Unit SW S&S
No charge, decline SW S&S
Per MSU SW S&S registration
Program name: IBM Tivoli zSecure Alert
Program PID: 5655-T11
Entitlement License option/
identifier Description Pricing metric
Basic OTC, per Value Unit
Basic OTC, per MSU-day TUC
S014725 zSecure Alert RACF
S014728 zSecure Alert ACF2
Subscription and Support PID: 5655-T12
Entitlement License option/
identifier Description Pricing metric
Basic ALC, per Value Unit SW S&S
No charge, decline SW S&S
Per MSU SW S&S registration
S014733 zSecure Alert -- RACF
S&S
S014736 zSecure Alert -- ACF2
S&S
Program name: IBM Tivoli Compliance Insight Manager Enabler for z/OS
Program PID: 5655-T15
Entitlement License option/
identifier Description Pricing metric
Basic OTC, per Value Unit
Basic OTC, per MSU-day TUC
S01473W Compliance Insight Manager
Enabler for z/OS -- RACF
S014748 Compliance Insight Manager
Enabler for z/OS -- ACF2
S014749 Compliance Insight Manager
Enabler for z/OS -- Top
Secret
S01474K Compliance Insight Manager
Enabler for z/OS -- DB2
Subscription and Support PID: 5655-T16
Entitlement License option/
identifier Description Pricing metric
Basic ALC, per Value Unit SW S&S
No charge, decline SW S&S
Per MSU SW S&S registration
S01473K Compliance Insight
Manager Enabler for
z/OS -- RACF S&S
S01474B Compliance Insight
Manager Enabler for
z/OS -- ACF2 S&S
S01474C Compliance Insight
Manager Enabler for
z/OS -- Top Secret
S&S
S01474W Compliance Insight
Manager Enabler for
Z/OS -- DB2 S&S
|
|
| Order now |
To order, contact the Americas Call Centers, your local IBM representative, or your IBM Business Partner.
To identify your local IBM representative or IBM Business Partner, call 800-IBM-4YOU (426-4968).
Phone: 800-IBM-CALL (426-2255)
Fax: 800-2IBM-FAX (242-6329)
Internet: callserv@ca.ibm.com
Mail: IBM Teleweb Customer Support
ibm.com Sales Execution Center, Americas North
3500 Steeles Ave. East, Tower 3/4
Markham, Ontario
Canada
L3R 2Z1
Reference: YE001
The Americas Call Centers, our national direct marketing organization, can add your name to the mailing list for catalogs of IBM products.
Note: Shipments will begin after the planned availability date.
Trademarks
