ACF2 (Access Control Facility 2) is a
commercial
Commercial may refer to:
* (adjective for) commerce, a system of voluntary exchange of products and services
** (adjective for) trade, the trading of something of economic value such as goods, services, information or money
* a dose of advertising ...
,
discretionary access control
In computer security, discretionary access control (DAC) is a type of access control defined by the Trusted Computer System Evaluation Criteria (TCSEC) as a means of restricting access to objects based on the identity of subjects and/or groups to ...
software security system developed for the
MVS (z/OS today),
VSE (z/VSE today) and
VM (z/VM today)
IBM mainframe operating systems
An operating system (OS) is system software that manages computer hardware and software resources, and provides common daemon (computing), services for computer programs.
Time-sharing operating systems scheduler (computing), schedule tasks for ...
by SKK, Inc. Barry Schrager, Eberhard Klemens, and Scott Krueger combined to develop ACF2 at
London Life Insurance in
London, Ontario
London is a city in southwestern Ontario, Canada, along the Quebec City–Windsor Corridor. The city had a population of 422,324 according to the 2021 Canadian census. London is at the confluence of the Thames River (Ontario), Thames River and N ...
in 1978. The "2" was added to the ACF2 name by Cambridge Systems (who had the North American marketing rights for the product) to differentiate it from the prototype, which was developed by Schrager and Klemens at the
University of Illinois
The University of Illinois Urbana-Champaign (UIUC, U of I, Illinois, or University of Illinois) is a public university, public land-grant university, land-grant research university in the Champaign–Urbana metropolitan area, Illinois, United ...
—the prototype name was ACF. The "2" also helped to distinguish the product from
IBM
International Business Machines Corporation (using the trademark IBM), nicknamed Big Blue, is an American Multinational corporation, multinational technology company headquartered in Armonk, New York, and present in over 175 countries. It is ...
's
ACF/VTAM.
ACF2 was developed in response to IBM's
RACF product (developed in 1976), which was IBM's answer to the 1974
SHAREbr>
Security and Data Management project's requirement whitepaper ACF2's design was guided by these requirements, taking a resource-rule oriented approach. Unique to ACF2 were the concepts of "Protection by Default" and resource pattern masking.
As a result of the competitive tension between RACF and ACF2, IBM matured the SAF (Security Access Facility) interface in MVS (now z/OS), which allowed any security product to process operating system ("OS"), third-party software and application security calls, enabling the mainframe to secure all facets of mainframe operations.
SKK and ACF2 were sold to
UCCEL Corporation in 1986, which in turn was purchased by
Computer Associates International, Inc. in 1987.
Broadcom Inc. now (2019) markets ACF2 as CA ACF2.
References
Operating system security
Computer access control frameworks
CA Technologies
IBM mainframe software
{{operating-system-stub