Select Page


Due diligence (DD) software package for mainframe outsourcers

The SF-DeepDive due diligence (DD) software package provides exactly what a mainframe outsourcer needs to get a clearer insight into given systems in a short amount of time.

When it comes to making decisions about the future of a mainframe, outsourcing is one option to consider. Of course, both sides involved in such a step have their own interests, and there is even tough competition among today’s outsourcing service providers.

Therefore, outsourcers definitely need an easy, early and deep insight into their potential “inheritance” and a curiosity about the quality and security of the given systems in terms of a clean and well maintained operating system, good security controls, proper compliance without vulnerabilities, well-established operational procedures via system automation, and other aspects. A failure of quality may result in additional costs and efforts that are hard to calculate; corresponding improvements have to be defined as prerequisites before responsibility can be fully undertaken, or can be offered as extra, paid services that are performed later.

The SF-DeepDive due diligence (DD) software package provides exactly what a mainframe outsourcer needs to get a clearer insight into given systems in a short amount of time. As an option, it can be combined with local assessment services from our company. As a kind of “Swiss Army Knife,” it provides all plug & play tools needed to deeply assess the quality and security of the configuration within a given mainframe infrastructure; if well prepared, it can be done in a one- or two-day visit. The outsourcer’s own technical experts can quickly gain a picture of their “inheritance” when they take over responsibility in the future.

SF-Sherlock’s automated 360 degree assessment and penetration simulation technologies for z/OS allow outsourcers to easily “X-ray” a potential customer’s mainframe platform to get a comprehensive view so as to fairly evaluate possible risks that would result from taking over the responsibility for a potential customer’s systems – that is, when doing a due diligence. One aspect concerns operational risks, that is, how clean and “rectangular” the given systems’ configurations are, and the other concerns security and compliance. SF-Sherlock’s comprehensive assessment report covers both aspects of quality with more than 1000 check points in total. Thanks to SF-Sherlock’s “easy installation” option, the outsourcer may perform such a “CT scan” of a given z/OS sysplex in one day. It has never been easier and more reliable to check on any “z inheritance.”

Apart from its “one shot use” for performing a deep dive during the due diligence phase, SF-Sherlock is also of great value later on. It allows outsourcers highly efficient, cost-effective and comprehensive 360-degree quality and security monitoring on clients’ mainframes so as to avoid problems through early identification. We are talking here about problems that may easily result in down times, breaches, or similar events, and, as a consequence, in “relationship problems” or even disputes. A classic feature as regards this early error detection is SF-Sherlock’s IPL simulation and constant parmlib verification. In this context, it can be connected to any SIEM, system automation or other monitoring solution, apart from sending emails.

To respond to the special demands on outsourcers in the current climate of high competition and steep obligations, we provide the option to add SF-SafeDump to the new SF-DeepDive solution package so as to perfectly fit the demands of outsourcers to provide cost-effective no-loss offers and to have all options for satisfying the expectations of more demanding clients with regards to today’s data protection, security and compliance obligations.

If you are an outsourcing service provider and think this could be of interest to your business and your team, please do not hesitate to contact us.


Over the past several years, compliance has become more and more an important issue, but also a tedious task. Our SF solutions assist you in automating the resulting workload to the max by also covering the entire mainframe platform - thanks to a 360-degree approach.


With SF-Sherlock, you can also protect your mainframe platform against attacks and combat high-level risks. Thanks to our max approach this also includes malicious code and exploits. Yes, both of these are real risks on the mainframe platform!

SF Solutions

All SF solutions are invented and developed in-house. Therefore, you can count on both our unique expertise and our high level of motivation in providing you with solutions and services with maximum performance, effectiveness, and productivity.

Are you expecting a governmental audit of your mainframe platform soon, as
by the BaFin, ECB, or one of
the “Big Four”?

Let us help you prepare your mainframe security and compliance.

+800 - 37 333 853 or simply dial: +800 - DRFEDTKE

Call our world-wide toll-free number now!

(+ represents the prefix for international calls; in most countries it is 00, and you have to dial 00800-37333853; in the U.S. it corresponds to 011)

News & IT Security Forum

System REXX and BCPii are the ”next APF“

If you look back along the evolutionary steps of mainframe security, APF libraries play a leading role – due to their “superpower.” Until the 1980s, “almost anyone” working on a mainframe was able and allowed to define one themselves. In most cases, there was no APF library protection at all. Then there was a phase where APF-related auditing received more and more attention, and correspondingly became an important audit issue.

The attention that “APF” received as a security risk has continued to increase over time. Today, it has almost reached the highest level of awareness: only a very few members of a company’s mainframe team are allowed to define a new APF library or update existing ones. Any such action requires prior permission, not just some documentation after it has happened. On our customer visits, we have seen companies where a new APF library requires not only an official change request, but up to “5 signatures.” Otherwise, you lose your job. Correspondingly, relentless monitoring and compliance reporting has become standard for the “APF” risk, resulting in real-time security alerts by a SIEM if corresponding rules are bypassed.

So far, so good. Now that there is great awareness of “APF,” the question will be if the entire mainframe security mission has now been accomplished? Or what’s the next superpower, following “APF,” that mainframe users need to focus on?

Based on our worldwide penetration testing experience, we have determined that “System REXX” and “BCPii” are two further members of the superpower league; both are good candidates for becoming the next “big focus.” In recent years, both z/OS features have been improved so that they are now “easy-to-use” functions. But there is no free lunch. As a consequence, highly critical operations became minimally complex, and you have to “pay” the price for setting up gap-free security measures. User-friendly and easy-to-use superpower features are an invitation to attackers. Complexity is a kind of protection. Compared to assembler programming or disassembling machine code, REXX programming is pretty trivial!

This is why SF-Sherlock focuses intensively on both of these areas. Please feel free to contact us to discuss additional details of what is necessary to properly protect System REXX and BCPii.

Join our newsletter list

Worldwide toll-free phone number

+800 - 37 333 853
or simply dial:

+41 (0)41 710 7444

(+ represents the prefix for international calls; in most countries it is 00, and you have to dial 00800-37333853; in the U.S. it corresponds to 011, and you have to dial 011-800-37333853)

Find Us


Seestrasse 3a, 6300 Zug, Switzerland

Visitors & Training

Dammstrasse 19, 6301 Zug, Switzerland

Social Media

Xing → Linkedin →

Write Us

copy the address

Technical support and hotline
copy the address

Legal and compliance
copy the address

error: Content is protected!