IBM i security risks can develop over years of routine operation and changing access requirements. Orphaned profiles, copied permissions, excessive authority, and consultant access can remain long after their original purpose disappears.
For IT leaders managing long-running IBM i environments, these issues can be difficult to see without a dedicated platform review. Organizations should look beyond perimeter security and examine what authority actually exists inside the system today.
Some persistent IBM i security risks develop inside the platform through user profiles, authority settings, and access that changes over time. An IBM i security audit can help identify those risks and establish a clearer baseline for remediation.
IBM i Security Requires Platform-Specific Review
IBM i uses an integrated object-security model that controls access to programs, files, libraries, devices, and other system resources. Every object can have authority settings defining which users may access it and what those users may do.
IBM also provides special authorities, including *ALLOBJ, *SECADM, *AUDIT, *SAVSYS, and other powerful system-level privileges. That design gives IBM i administrators detailed control over access, but it also makes authority management an important part of security administration.
Security professionals who primarily work with other platforms may not routinely examine IBM i authority structures at that level. General vulnerability tools may also provide limited visibility into object authority, adopted authority, special authorities, and IBM i user-profile relationships.
IBM provides dedicated security assessment tools and guidance specifically because these settings deserve platform-level review. The IBM i object-based security model is powerful, but organizations still need to confirm that authority matches current business requirements.
Three IBM i Access Risks Worth Reviewing
Several access issues can develop over time as users, roles, applications, and outside resources change.
- Excessive authority that remains longer than necessary. A user may receive additional authority for a project, application change, or temporary responsibility. That access may remain in place long after the original business need has ended.
- Profile accumulation and copied permissions. Organizations sometimes create new profiles from existing ones because the process is fast and familiar. Over time, unnecessary permissions or dormant profiles can remain active.
- Temporary outside access that was never removed. Consultants and technical specialists may receive elevated authority for upgrades, migrations, or troubleshooting. That access should be reviewed and removed after the engagement ends.
IBM recommends reviewing temporary authority and overall security as responsibilities and system environments change. Read our post about common IBM i security vulnerabilities for additional guidance on those areas.
Inside an IBM i Security Audit
A general compliance review and an IBM i platform assessment do not necessarily surface the same vulnerabilities. Compliance reviews may focus on policies, documented controls, evidence, user procedures, and the requirements included within the audit scope. An IBM i security audit goes deeper into the system's configuration.
The goal is to establish a baseline and identify issues that deserve attention based on their actual risk level. The organization can then prioritize findings and address higher-risk items before less critical configuration improvements.
Security assessment costs vary by provider, environment size, number of LPARs, assessment depth, and required remediation. Some vendors offer introductory scans, while deeper assessments and remediation projects require a more detailed scope and quote.
Temporary privileged access is one issue a security assessment can uncover. Bob Losey has spent more than four decades watching organizations discover IBM i risks they did not know existed.
"I've heard cases where a trusted consultant came in, was given the highest level of security, sets up a backdoor, quits, and then goes online to get further information or do nefarious stuff. With the AS/400, I think I've read or been told somewhere that 60 or 70 percent of all the hacks were a result of that. An insider came in, was not detected, and his profile was not turned off." – Bob Losey, Founder and President, Source Data Products
IBM i Security Requires Ongoing Review
IBM i security is not something you configure and then just forget about until an issue comes up. Users change roles, applications evolve, consultants complete projects, new services are enabled, and authority requirements change as part of normal business operations. IBM continues publishing security bulletins and PTFs addressing IBM i and components running within the broader IBM i environment.
Recent security bulletins have addressed IBM i itself along with OpenSSH, OpenSSL, Java, and other supported components. That makes PTF currency another important part of ongoing IBM i security management. Source Data's IBM i Managed Services include PTF status monitoring, scheduled PTF installation, OS management, and high-scoring CVE remediation.
Source Data currently reviews and schedules IBM PTFs, with approved PTF installation coordinated around the client's operating schedule. Organizations also need to pay attention to the support lifecycle of the IBM i release they currently operate. IBM i 7.4 remains within standard support through September 30, 2026, with Service Extension available through September 30, 2029.
That distinction matters because support terms and available service options change after the standard support period ends. Organizations running older releases should review their upgrade plans rather than assuming the same support model continues indefinitely.
Two Layers of IBM i Security to Review
The IBM i security conversation generally includes both infrastructure controls and platform-specific controls. The infrastructure layer supports data center security, network resilience, backups, patch management, monitoring, and disaster recovery planning.
For hosted environments, Source Data's Cloud400 service provides managed infrastructure and IBM i expertise around those operational responsibilities. The platform-specific layer includes user profiles, special authorities, object permissions, system values, exit points, and other IBM i controls.
Moving an IBM i workload into a hosted environment does not automatically correct authority or profile issues already inside the LPAR. Those settings still require review, even when the underlying infrastructure is professionally hosted and managed.
This distinction matters because both areas contribute to the overall security posture of an IBM i environment. If your organization has not performed a dedicated IBM i security assessment, the current platform configuration may still contain unanswered questions.
A review can provide a clearer baseline before those questions arise during an audit, insurance review, application change, or security event.
Common Questions About IBM i Security Audits
What is IBM i object-based security and why does it matter?
IBM i uses integrated object security to control access to files, programs, libraries, devices, and other system resources. Authority determines which users can access an object and which operations they are allowed to perform against that resource. This approach provides detailed access control, but organizations still need to review authority as users and business responsibilities change.
How do internal access risks develop in IBM i environments?
Internal access risks can develop through excessive authority, dormant profiles, copied permissions, and temporary privileged access that remains after its purpose ends. These issues usually develop gradually as employees, contractors, applications, and organizational responsibilities change over the life of the system. Regular access reviews help confirm that current authority still matches each user's actual responsibilities.
Will a standard compliance audit catch IBM i security problems?
That depends on the scope of the audit and how deeply the auditor examines the IBM i environment. A policy-focused audit may confirm controls without reviewing every IBM i user profile, object authority, or special-authority relationship. A platform-specific IBM i assessment provides a more detailed review of system configuration and authority settings.
How much does an IBM i security assessment typically cost?
IBM i security assessment costs vary based on the system size, number of LPARs, assessment depth, and remediation requirements. Some providers offer introductory assessments at no cost, while comprehensive reviews require customized pricing.
What is a PTF and how does it relate to IBM i security?
A Program Temporary Fix, or PTF, is IBM's mechanism for delivering corrections and updates for IBM i and related software. Security bulletins often identify specific PTFs customers should install to address documented vulnerabilities affecting supported IBM i environments. Keeping PTFs reasonably current therefore supports both system maintenance and the organization's broader security program. Source Data's IBM i Managed Services include PTF monitoring, planning, and approved installation as part of ongoing system management.
Can moving IBM i to a hosted environment improve security?
Hosting can improve several infrastructure controls by providing managed hardware, data center protections, monitoring, backups, and professional IBM i administration. It does not automatically correct existing user authority, dormant profiles, excessive privileges, or application-level security settings inside the LPAR. Infrastructure security and platform configuration should therefore be reviewed as separate but related parts of the overall security program.
How often should an IBM i security review be conducted?
IBM recommends performing an IBM i security assessment annually because system configurations and security requirements continue changing over time. Organizations should also review user access whenever employees leave, responsibilities change, consultants finish engagements, or privileged access is no longer required. Environments that have never completed a platform-specific assessment should establish a current baseline before deciding on the appropriate ongoing review schedule.
What is the difference between IBM i security and general cybersecurity compliance?
General cybersecurity frameworks establish broader requirements for areas such as access control, monitoring, risk management, and documented security procedures. IBM i security applies those principles within the platform's specific profiles, authorities, objects, system values, services, and audit functions. The two approaches support each other, but the depth of IBM i configuration review depends on the scope of the compliance assessment. A successful broader compliance review therefore should not replace regular platform-specific security administration.
Get a Clearer View of Your IBM i Security Posture
IBM i provides strong built-in security controls, but those controls must reflect your organization's current environment. Profiles, authority, PTF levels, applications, consultants, and business responsibilities can all change during the life of a system.
A security audit helps identify where current settings still match business needs and where adjustments may strengthen the environment. Infrastructure security and IBM i platform security also require different types of review, even though both support the same overall goal.
Source Data helps IBM i organizations strengthen operations through managed services, hosting, upgrades, disaster recovery, and long-term infrastructure planning. For a practical review of your IBM i environment, start a conversation with the Source Data team.
ABOUT THE AUTHOR
Bob Losey | Founder & President, Source Data Products | 45+ years in IBM midrange systems since 1979 | 4,000+ clients served | Premier IBM Business Partner | Developer of Cloud400 hosting platform | IBM i Technical Certifications (2000-2020) |


