This document discusses security models for WebSphere applications on z/OS and how they integrate with RACF. It begins by providing background on RACF and traditional mainframe security concepts. It then explains the Java security model and how RACF implements J2EE roles using new EJBROLE and GEJBROLE classes. It compares this approach to CICS security and how user IDs are propagated downstream. The document aims to help mainframe and Java practitioners communicate by translating between the different security perspectives.