Architecture

IBM i Security Architecture Guide

IBM i security is not one control, it is a stack. Each layer below depends on the ones before it: authentication is worthless if authority is unmanaged, and authority is worthless if there is no auditing to catch misuse.

The stack below reflects the order we recommend addressing IBM i security architecture in, not an arbitrary list. Multi-factor authentication establishes who is on the system. Privileged access management controls what elevated profiles can do once signed on. Authority management right-sizes what every other profile can touch. Encryption and database security protect the data itself. Auditing and logging catch what the earlier layers miss. Each guide below covers requirements, implementation, and the vendors that cover that layer well.

More From the AS/400 and IBM i Research Network