Posts Tagged ‘Auditing’

Don’t Gamble with Your Audit

Posted in Auditing on October 13th, 2009 by Robin – Be the first to comment

It’s always an eye-opening experience to speak with an auditor about the intricacies of auditing an IT environment. I respect their views, and I can only imagine how difficult it is trying to be an expert on the wide variety of technologies found in an average enterprise.

Last week, I spent a couple of days at the ISACA conference in Las Vegas, meeting and talking with auditors from around the country. While some had heard of the System i (or iSeries or AS/400), it was very evident that there weren’t any subject matter experts on hand. I was left wondering: “How can anyone receive an effective audit of a platform that IT auditors have such limited knowledge of?”

PowerTech security experts perform a healthy number of audits each year, but there are not many firms with our professional capabilities. Yet, we’re barely scratching the surface of the immense number of organizations that must maintain compliance with the seemingly-endless list of regulations and legislations found throughout the world. What about the others—are they just ignoring the mandates? Or, are they being subjected to questionable recommendations made from a comparison to an old checklist compiled from numerous online sources. I fear it’s probably a mix of the two!

PowerTech developed the wildly popular Compliance Assessment tool to perform a review of six major areas of vulnerability. We have made this tool available to users as a free service, and now include one-on-one time with a security expert to help interpret the findings. The auditors I talked to were extremely excited to know that there was someone out there to help make their lives easier, and to be an expert they can talk to when they encounter a System i. I’m excited and encouraged at the opportunities that brings to the PowerTech table as we continue to grow, and as we continue to service the IBM i community with world-class security solutions.

While you might not think of an IBM i-savvy auditor as a benefit, the fact that you’re talking with someone who understands real-world vulnerabilities, as well as the inherent strengths of security on the platform, adds protection to your corporate data. And the availability of a speedy tool that provides an educated view into the infrastructure makes your IBM i data even safer.

And, after all, isn’t that the purpose of a security audit in the first place?

An Auditors View—Assessing Your System i in 15 Minutes—for Free!—Webinar 10/28/2009

Posted in Webinars on October 9th, 2009 by Christopher – Be the first to comment

For the past six years, PowerTech has compiled audit data trends from over 1,500 servers into the annual “State of System i Security” study. Each study has identified many of the same vulnerabilities, suggesting that System i shops are still not where they need to be in terms of security and auditing.

Join Robin Tatam, Director of Security Technologies at PowerTech, in this webcast where you will learn how to get started auditing the System i platform, including free use of PowerTech’s compliance assessment tool to perform a personalized review of your own environment – in under 15 minutes!

You will learn about performing an audit of these important areas:

  • System Values
  • Network Access such as FTP and ODBC
  • User Profiles
  • Special Authorities
  • Event Auditing

Attendees are eligible to receive a FREE compliance assessment.

Presenters
Main Presenter: Robin Tatam, PowerTech
Co-presenter: Jill Martin, PowerTech

Wednesday, October 28, 2009
8 a.m. Pacific / 10 a.m. Central / 11 a.m. Eastern
Check our chart for your local time >

Cost
Free of charge

Registration
To register, please visit our WebEx site.

Speaker Bio
robin-headshotRobin Tatam is the Director of Security Technologies for PowerTech, a leading provider of security solutions for the System i. As a frequent speaker on security topics, he was also co-author of the Redbook IBM System i Security: Protecting i5/OS Data with Encryption. Robin can be reached by email at robin.tatam@powertech.com.

“Who Done It?” Solving an ‘i’ Audit Mystery Webinar—10/14/2009

Posted in Webinars on October 1st, 2009 by Christopher – Be the first to comment

At one time or another, every administrator and Security Officer will face the question “who did it?” The IBM i operating system includes a facility to audit certain user activities, and you need to use it. However, once the event data is collected the challenge becomes how to disseminate the raw data into useful information.

Join this webinar to understand:

  • How to configure the IBM i operating system to record system and user events
  • What types of activities can (and cannot) be audited
  • What other information an Auditor wants to see
  • How to step up to the next level of audit reporting with PowerTech Compliance Monitor

You will also learn about what system auditing does not capture, and how to prevent that from causing you to fail an audit.

Attendees are eligible to receive a FREE compliance assessment.

Presenters
Main Presenter: Robin Tatam, PowerTech
Co-presenter: Paul Culin, PowerTech

Wednesday, October 14, 2009
8 a.m. Pacific / 10 a.m. Central / 11 a.m. Eastern
Check our chart for your local time >

Cost
Free of charge

Registration
To register, please visit our WebEx site.

Speaker Bio
robin-headshotRobin Tatam is the Director of Security Technologies for PowerTech, a leading provider of security solutions for the System i. As a frequent speaker on security topics, he was also co-author of the Redbook IBM System i Security: Protecting i5/OS Data with Encryption. Robin can be reached by email at robin.tatam@powertech.com.

Configuring IBM i Auditing Features Webinar—10/7/2009

Posted in Webinars on September 24th, 2009 by Christopher – Be the first to comment

Did you know that IBM i includes powerful auditing features? In fact, our own class-leading audit reporting solution leverages the information captured by this facility. Join this webinar—based on content presented at the 2009 COMMON conference—to learn about activating and configuring IBM i’s built-in auditing capabilities.

In this webinar you will learn about:

  • Security audit journal
  • Audit data management
  • Configuring the ‘Audit’ system values
  • A user profile’s *AUDIT special authority
  • Object auditing
  • User auditing
  • Basic reporting capabilities
  • Advanced reporting options

You will also learn about what system auditing does not capture, and how to prevent that from causing you to fail an audit.

Attendees are eligible to receive a FREE compliance assessment.

Presenters
Main Presenter: Robin Tatam, PowerTech
Co-presenter: Jill Martin, PowerTech

Wednesday, October 7, 2009
8 a.m. Pacific / 10 a.m. Central / 11 a.m. Eastern
Check our chart for your local time >

Cost
Free of charge

Registration
To register, please visit our WebEx site.

Speaker Bio
robin-headshotRobin Tatam is the Director of Security Technologies for PowerTech, a leading provider of security solutions for the System i. As a frequent speaker on security topics, he was also co-author of the Redbook IBM System i Security: Protecting i5/OS Data with Encryption. Robin can be reached by email at robin.tatam@powertech.com.