How to prevent or secure DESKEYLBL JCL parameter usage in JCL.
To prevent any user in TSS from specifying DSKEYLBL in the JCL:
TSS PER(ALL) IBMFAC(STGADMIN.SMS.ALLOW..ENCRYPT) ACCESS(NONE)