云题海 - 专业文章范例文档资料分享平台

当前位置:首页 > IBM AS400 Security Procedures

IBM AS400 Security Procedures

  • 62 次阅读
  • 3 次下载
  • 2025/5/25 17:31:45

Auditor(s) Assigned Audit Date

Workpaper

Audit Objectives and Procedures Ref. By

________________________________________________________________________________________________________

K.8

K.8.3

System Logs -Cont'd If the system log is not used, determine if the auditing journal (QAUDJRN) is generated and reviewed.

The Security Officer can monitor security by gathering audit information about specific security-related events. This can be achieved by performing the following steps:

(1) Create journal receiver:

CRTJRNRCV JRNRCV(user-lib/user-name1) AUT(*EXCLUDE)

(2) Create journal:

CRTJRN JRN(QSYS/QAUDJRN) JRNRCV (user-lib/user-name1) AUT(*EXCLUDE)

(3) Change system value:

CHGSYSVAL QAUDLVL VALUES ('AUTFAIL *SECURITY *PGMFAIL ...'

The QAUDLVL values control which security-related events are logged to this journal. E&Y recommended QAUDLVL values are as follows:

? AUTFAIL - logs all access authorization failures;

? SECURITY - logs security-related activities, such as those

related to object authority, user profiles, and system values; and

? PGMFAIL (security level 40) - creates an authorization failure

entry for each object domain, blocked instruction or program validation check failure.

K.8.4

Ensure that there are inquiry letters written by the Security Officer to the users' heads of department when significant access violations are detected by the logging facility. Also review the responses received from the users' heads of department explaining the violations.

Determine if a procedure is in place to provide a report to each user department identifiying the respective department's responsible transactions (especially update) and the authorized users for those transactions. The reports should be provided not less than every 6 months. Verify the authorizations.

K.8.5

SYSTEM SECURITY

K/PROG

Page 22 of 22

40

Auditor(s) Assigned Audit Date

Workpaper

Audit Objectives and Procedures Ref. By

________________________________________________________________________________________________________

L. Physical Inventory

1. Leases/contracts are available and in force for hardware, including

peripheral equipment, and software.

2. Lists of existing equipment is complete and current (including all

PCs).

3. Determine procedure for disposing of equipment.

4. Validate equipment to the Asset list.

PHYSICAL INVENTORY

L/PROG

41

Page 1 of 1

Auditor(s) Assigned Audit Date

Workpaper

Audit Objectives and Procedures Ref. By

________________________________________________________________________________________________________

M. System Performance Monitoring

1. Are there performance standards established?

If not, what is the allowable limits of: a. Response time b. Disk Capacity

2. What capacity planning is performed with new systems

development?

3. Is a report provided management depicting system performance?

If yes, how frequent?

SYSTEMS PERFORMANCE MONITORING

M/PROG

N. Preventative Maintenance (PM)

42

Page 1 of 1

Auditor(s) Assigned Audit Date

Workpaper

Audit Objectives and Procedures Ref. By

________________________________________________________________________________________________________

1. Insure Preventative Maintenance agreements are available.

a. Time period (Start and ending PM dates). b. Equipment description. c. Frequency of PM

d. Charge per call or per year.

2. Insure PM is performed on contracted equipment only.

PREVENTATIVE MAINTENANCE

43

N/PROG

Page 1 of 1

搜索更多关于: IBM AS400 Security Procedures 的文档
  • 收藏
  • 违规举报
  • 版权认领
下载文档10.00 元 加入VIP免费下载
推荐下载
本文作者:...

共分享92篇相关文档

文档简介:

Auditor(s) Assigned Audit Date Workpaper Audit Objectives and Procedures Ref. By _______________________________________________________________________________________

× 游客快捷下载通道(下载后可以自由复制和排版)
单篇付费下载
限时特价:10 元/份 原价:20元
VIP包月下载
特价:29 元/月 原价:99元
低至 0.3 元/份 每月下载150
全站内容免费自由复制
VIP包月下载
特价:29 元/月 原价:99元
低至 0.3 元/份 每月下载150
全站内容免费自由复制
注:下载文档有可能“只有目录或者内容不全”等情况,请下载之前注意辨别,如果您已付费且无法下载或内容有问题,请联系我们协助你处理。
微信:fanwen365 QQ:370150219
Copyright © 云题海 All Rights Reserved. 苏ICP备16052595号-3 网站地图 客服QQ:370150219 邮箱:370150219@qq.com