The Hidden Risk in Your z/OS Environment

Mar 31, 2026

Hugo Prittie is the CEO of Action Software GmbH based in Switzerland. With over 56 years’ experience in IBM Mainframes including 10 years at IBM, 22 years as an MVS consultant all over Europe and 25 years as CEO and CTO.

In today’s always-on environments, changes to z/OS systems are happening constantly—often dynamically, and often under time pressure.

While most organizations have formal change management processes in place, these processes are frequently reactive rather than preventative. They document what should happen, but don’t always ensure what actually does happen at the system level.

That gap introduces real risk.

Uncontrolled or poorly managed system changes can lead to:

  • Service disruptions or outages
  • Incomplete audit trails and compliance exposure
  • Difficulty identifying and reversing problematic changes

As systems grow more complex and availability expectations increase, these risks become harder to manage through process alone.

Why Traditional Change Management Falls Short

Frameworks such as SOX, GDPR, and DORA emphasize the importance of strong controls—but they don’t prescribe how to enforce those controls across the wide range of tools and methods used in z/OS environments.

In practice, systems programmers must make changes using many different utilities, commands, and interfaces. Without a way to track, control, and validate these changes in real time, organizations are left relying on:

  • Manual processes
  • After-the-fact auditing
  • Trust that approved changes match actual changes

This creates exposure—not just operationally, but from a compliance and governance standpoint.

Moving Toward Real-Time Change Control

To address these challenges, many organizations are shifting toward automated, real-time approaches to change management.

These approaches focus on:

  • Intercepting changes as they occur
  • Ensuring only authorized changes are executed
  • Maintaining a complete, accurate audit trail
  • Enabling fast and reliable rollback when needed

For organizations looking to strengthen control without increasing operational burden, a more detailed framework can help guide implementation.

Putting This Into Practice

Action Software International’s flagship product, eventACTIONTM is a comprehensive event handling tool that provides unique and powerful real-time z/OS capabilities by automatically detecting and managing system events as they occur. This event driven approach allows you to automatically and transparently:

  • Track, control, backup and restore changes to z/OS system data sets or members
  • Track references to z/OS system data sets or members
  • Track and control system commands
  • Ensure that program products execute only on licensed systems
  • Propagate changed data to other systems

Today’s systems programmers must ensure maximum reliability and availability for larger and increasingly complex z/OS environments while staffing levels stay the same or decrease. At the same time, they must satisfy stringent audit and compliance requirements with frameworks such as Sarbanes-Oxley (SOX), ITIL, HIPAA, BASEL II, COBIT and EU-GDPR.

Meeting the Effective Change Management Challenge 

An effective change management system will automatically prevent unauthorised changes, track and backup authorised changes, and provide for coordinated back-out of unsuccessful changes. Only an automated system with real-time change interception capabilities can ensure that only the changes that have been authorised are actually made. Similarly, only an automated full-spectrum process with comprehensive tracking and automated backups can provide full documentation of the changes made, as well as a fast-reversal of changes and quick business continuation in the event of a problem.

eventACTION Component Solutions

All eventACTION and ussACTION components record tracking information to a database, where detailed information on tracked events can be retrieved instantly. A powerful compare facility allows analysis of changes. Batch reports, email and a job scheduler facilitate the distribution of tracked events on a regular basis. Together, these capabilities improve systems management productivity and ease the burden of satisfying compliance requirements.

  • eventACTION solutions track every change, creating a secure audit trail. They also prevent unauthorised changes from being made. Backups are created when changes are detected and can quickly be restored.
  • eventACTION’s Reference Tracker component provides several ways to track what PDS/PDSE members are being used and who is using them.  These facilities are useful for tasks such as detecting who is using different versions of products, and library cleanup.
  • Command Manager allows tracking and controlling the use of operator commands. The site can specify what commands should be tracked and/or controlled.
  • Product Execution Manager can be used to ensure compliance with software agreements by ensuring that products only run on those systems on which they are licenced.
  • The Communications Manager and Distribution Manager provide facilities for propagating both data set changes and eventACTION definitions between systems.
  • The Event Logger allows real-time propagation of events to an external product such as a SIEM.
  • ussACTIONTM provides functionality on z/OS USS (UNIX System Services) similar to that provided by eventACTION on z/OS MVS.

In Summary

Action Software International’s z/OS MVS and z/OS USS change management tools are widely deployed within Global 2000 companies, institutional and government sites worldwide.

EventACTIONTM  for z/OS MVS Components:

  • Change Tracker
  • Change Manager
  • Reference Tracker
  • Command Manager
  • Product Execution Manager
  • Communications Manager
  • Distribution Manager
  • Event Logger

ussACTIONTM  for z/OS USS Components:

  • Change Tracker
  • Change Manager
  • Reference Tracker
  • Event Logger

Request a free trial or demonstration

Contact Action Software to learn how eventACTION can support your environment.

About Us

Action Software International is a division of Mazda Computer Corporation. Located in Toronto, Canada, Mazda Computer Corporation has been producing superior systems and network management software since 1980. The Company’s products are widely deployed within Global 2000 companies, as well as numerous government and institutional sites. Mazda Computer Corporation’s mission is to provide easy to use high performance systems management solutions to the IBM z/OS system user community, based on highly functional products and exceptional customer service.

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *

Sign up to receive the latest mainframe information

This field is for validation purposes and should be left unchanged.

Read More

The Need for Effective Change Management

The Need for Effective Change Management

Introduction Over the last few years there has been an ever-increasing number of widely publicised problems involving notable corporate organisations and the failings of their IT systems.  Incidents of ransomware, hacking and phishing are becoming worryingly...

The Real Opportunity for AI on the Mainframe Isn’t Code

The Real Opportunity for AI on the Mainframe Isn’t Code

AI for the Mainframe: Turning System Data Into Answers For the past year, nearly every conversation about artificial intelligence and the mainframe has centered on one question: What will AI do to COBOL? Will it modernize legacy applications? Generate new programs?...