Anything can be compromised, however traditional mainframe configurations are very well structured so generally it is considered much harder than, for example, an average server running PHP:-)
Start with one of the security hardening guides for your mainframe. If you are running IBM, the manuals on IBM mainframe security will give you 95% of what you need.Start with the redbooks. The one I have linked to is over 500 pages and it is just one of many!
That said - if you are new to mainframe security, you really shouldn't be going anywhere near a mainframe. Generally they run high value data and tools...