Use Case - Forensic Analysis

Keeping business processes auditable and transparent
In auditing, the analysis of user activities is essential, and log files provide an important source of information for this purpose. When configured properly, operating systems and applications keep an extensive record of all activities by logging data from their own processes. Where central servers and host systems are used, saving these log data is a routine task. They are then available for audit and analysis any time the need might arise. Tried and tested procedures ensure the thoroughgoing documentation of all processes, and provide both auditors and administrators with the means of pinpointing any weak points that could lead to security risks. This is the only way of ensuring compliance with the multitude of rules and regulations governing the transparency and auditability of business process, which, today, are mainly IT processes.

Weak point – distributed systems
These days IT processes are no longer handled exclusively by a central server; the job stream also includes a lot of decentrally administered systems. Unfortunately, not always enough is done to ensure the adequate storage of log data from these systems. If log data are saved at all, a wide variety of different processes and archiving systems are used, generally adding to the confusion rather than providing the transparency that's needed. However, the transparency and auditability of processes can only be guaranteed if they are examined in their entirety. This means that an enterprise needs to keep all its log data in a central archive. Even for a medium-sized business, that could involve the administration of terabytes of information every year.

A necessity – powerful log administration
User activities in business processes can only be fully documented when the log data from all the computers and applications are stored centrally. The processes and tools used to achieve this aim must ensure that data are archived is such a way as to be fraud-proof, and that information can be accessed fast whenever the need arises. The central administration of log archiving is a vital precondition for the enforcement of security policies and compliance with statutes and regulations.

The Beta 92 Enterprise solution makes the many years of experience gained in handling enormous quantities of log data in a mainframe landscape available to distributed systems. Using a central administration interface, it is possible to configure the mode of operation of agents on systems such as Windows, UNIX or SAP R/3. All the data are archived in the system's central database and can be accessed whenever needed. Thus Beta 92 not only ensures that forensic analysis can be carried out at any time, but also provides the enterprise with proof of compliance with the increasing demands made by the laws and regulations governing data security in this important sector.