SSIM Questions
Hello all
I have some questions regarding compliance points we have received in an RFP to check against SSIM. I hope you assist me:
1) The system should have the ability to collect logs without enabling "Audit Trail" in database
2) The solution should have the ability to process data from the last point of failure
3) Stateless and stateful rule based correlation (I don't know what is this exactly!)
4) The solution should have the ability to deal with Oracle e-business suite Database & Application tier specific events such as (what forms/views are assigned to users, who is accessing confidential information, did the DBA granted others access to confidential information)
5) The solution should have the ability to deal with Microsoft File and Print Sharing security events such as (who have done changes in network shared folder “DFS”, who have deleted or modified a specific folder / file, when did they’ve done it and what confidential documents were printed …etc.)
6) Support for the folowing systems:
- Microsoft Windows 2003 Storage Server build 3790
- Huwaie VRP (an operating system)
- Blue-Coat IOS
- NetScreen IOS
- Informix Database
- Oracle Business Suite 11
- Citrix
- Cisco IPCC
- Microsoft Office Communicator
- TACACS+
- AAA
Many thanks in advance...
Comments
1) The system should have
1) The system should have the ability to collect logs without enabling "Audit Trail" in database
This is technically not possible, if you don't enable auditing in general, it is vera hard for any product to collect audit log. What sort of logs are they interested in ? (if you take the example of an Oracle database, this is an Oracle recommendation to enable DBA_AUDIT_TRAIL if you want to collect descent information.
Unfortunately
Hi Laurent_c
I was like 99% sure it won't be possible without enabling "audit trails". (so I'm stuck now!)
But I'm wondering. What about other listed points?
Thank you...
Would you like to reply?
Login or Register to post your comment.