iSecurity AP Journal Training
iSecurity Overview: AP-Journal Audit Capture User Management System Control User Profile Replication System Value Replication Central Admin 3 Auditing 7 Evaluation 1 PCI, HIPAA, SOX or Security Breach or Management Decision 4 Protection Firewall Authority on Demand Anti-Virus Screen Password Action Native Object Security 2 Assessment Compliance Evaluator Visualizer 5 Databases AP-Journal View FileScope 6 8 2
The Challenge Unless you use AP-JOURNAL! Vendor A Vendor B Vendor C GL AP Banking AR Claims It is possible to get information about any aspect regarding “33589-10”; BUT there is no way to get information: From ALL systems/applications In TIME order Showing IMPORTANT business data (i.e. Business Items) and Before/After data Who made the changes, from which IP address and more Unless you use AP-JOURNAL!
AP-Journal Business Examples Provide the customer with a timeline report showing MORTGAGE history of the last 5 years. Include only important info. Send Mail, SMS, SNMP, SYSLOG, when the INTEREST_RATE changes by more than 0.2%. Who modified PAYMENTS between 20:00 and 06:00 or during corporate summer vacation? When did the tariff for overseas transactions change? Which users, who are not Managers, viewed the confidential PAYMENT_TERMS table since the last business day? What changes to the bank’s production libraries were made via IBM utility DFU?
Output & Alert capabilities Reporting - Screen, Print, GUI, HTML, PDF, Output file While querying (in GUI or Screen), user can continually refine the selection criteria Once satisfied – keep the selection as a report Schedule to run periodically Set recipients Every report includes explanation at end (for Auditors, Customers) Alerts - composed as text which contain fields from the event sent by: Email SMS Message queues (e.g. QSYSOPR) Syslog, SNMP for SIEM (centralized console systems) Twitter (web based “console”)
AP-Journal Technical Overview DB1 DB2 DB3 Business Items B Journal A Long-time storage for critical data DB-Reads Processing of Receivers in Real time (or at night) C D Alert Before E F Alert After Receivers Containers G Reporting System G Reporting System Screen Email & HTML Print-out
Before and After Values of changed fields Update of Order File from specified IP Address changed PRICE; displaying Before/After values
HTML Report Update and Write operation details with Current and Before Values displayed
Display of Database Update Display data before & after any changes which were made from a specific IP address
AP-Journal Visualizer: Filters and Fields Filter by field data and view summary statistics by transaction fields
How to set up AP Journal Activate AP Journal Journal the objects Create an “application” Define filters and actions Enable the application Start Real Time Collection Create reports
Example Application