Use Case - Forensic Analysis
Keeping business processes auditable and transparent
In auditing, the analysis of user activities is essential, and log files provide an important
source of information for this purpose. When configured properly, operating systems and
applications keep an extensive record of all activities by logging data from their own processes.
Where central servers and host systems are used, saving these log data is a routine task. They are
then available for audit and analysis any time the need might arise. Tried and tested procedures
ensure the thoroughgoing documentation of all processes, and provide both auditors and
administrators with the means of pinpointing any weak points that could lead to security risks.
This is the only way of ensuring compliance with the multitude of rules and regulations governing
the transparency and auditability of business process, which, today, are mainly IT processes.
Weak point – distributed systems
These days IT processes are no longer handled exclusively by a central server; the job stream
also includes a lot of decentrally administered systems. Unfortunately, not always enough is done
to ensure the adequate storage of log data from these systems. If log data are saved at all, a wide
variety of different processes and archiving systems are used, generally adding to the confusion
rather than providing the transparency that's needed. However, the transparency and auditability of
processes can only be guaranteed if they are examined in their entirety. This means that an
enterprise needs to keep all its log data in a central archive. Even for a medium-sized business,
that could involve the administration of terabytes of information every year.
A necessity – powerful log administration
User activities in business processes can only be fully documented when the log data from all
the computers and applications are stored centrally. The processes and tools used to achieve this
aim must ensure that data are archived is such a way as to be fraud-proof, and that information can
be accessed fast whenever the need arises. The central administration of log archiving is a vital
precondition for the enforcement of security policies and compliance with statutes and regulations.
The
Beta 92 Enterprise
solution makes the many years of experience gained in handling enormous quantities of log data in a
mainframe landscape available to distributed systems. Using a central administration interface, it
is possible to configure the mode of operation of agents on systems such as Windows, UNIX or SAP
R/3. All the data are archived in the system's central database and can be accessed whenever
needed. Thus Beta 92 not only ensures that forensic analysis can be carried out at any time, but
also provides the enterprise with proof of compliance with the increasing demands made by the laws
and regulations governing data security in this important sector.
