IBM Security zSecure 2.4.0 Event Correlation And Compliance Automation Service Stream Enhancement (OA61058, OA61059) Documentation Updates - IBM Security zSecure Alert User Reference Manual IBM Chapter 1. About this document This document describes the documentation updates as a result of the zSecure event correlation and compliance automation Service Stream Enhancement (SSE, for APAR numbers OA61058 and OA61059 - April 2021). The following enhancements were made: • End-to-end event correlation between IBM® z/OS® Connect, CICS®, and Db2® events • Support for a new layout of SMF record type 123, subtype 1 (z/OS Connect) • Alerts 1124 (RACF®) and 2124 (CA ACF2) for a TSO logon from an IP address that is not allow-listed • Support for tape data set sensitivities • Ability to evaluate STCs through STIG by using a Site Security Plan approach • More STIG automation (5 controls for CA ACF2, 3 controls for IBM RACF and CA Top Secret) and other STIG-related improvements, such as ensuring a result when no objects are evaluated • More reporting of ICSF settings • Audit concern for UACC of ID(*) access of ALTER to discrete profiles • Ability to use CARLa literals for sorting only (NONDISPLAY) • Ability to sort command output from RECREATE by profile • Ability to use longer messages and descriptions in alerts • Ability to show OPERROUT in exploded format • Performance improvements for zSecure support for CA ACF2 The documentation updates apply to 2.4.0 zSecure Admin, zSecure Audit, and zS