Part 3 – Security & Concurrency
Understanding how Db2 manages transaction integrity, locking behavior,
and secure access control in enterprise production environments.
Concurrency & Locking
- Isolation levels: UR, CS (default), RS, RR
- Lock modes: Shared (S), Exclusive (X), Intent locks
- Lock escalation governed by LOCKLIST and MAXLOCKS
- Deadlocks vs lock timeouts — understand the difference
- Use MON_GET_CONNECTION and sysibmadm.mon_lockwaits for diagnostics
Security & Access Control
- Authentication vs Authorization
- Authorities: SYSADM, DBADM, SECADM, DATAACCESS
- Implement separation of duties
- Prefer Roles over direct user grants
- Review catalog authorization views regularly
Advanced Protection
- TLS encryption for data in transit
- Db2 native encryption for data at rest
- Row and Column Access Control (RCAC)
- Trusted Context for 3-tier architectures
- Audit policies for compliance and traceability
Key DBA Takeaways
- Short transactions reduce lock contention
- Monitor deadlocks proactively
- Enforce least privilege at all levels
- Encrypt both in transit and at rest
- Always design for both performance and security together