Monitoring Authorized User Activities: The Importance of a Sound Forensic Audit Trail
Jan 01, 0001
Jan 01, 0001
According to a recent study on Insider Threat conducted by the Ponemon Institute, organizations suffer an average of more than 52 incidents of insider fraud annually. Traditional security controls, such as application logging, are often powerless in these situations.
July 2012
Sponsored by Attachmate Luminet®
According to a recent study on Insider Threat conducted by the Ponemon Institute, organizations suffer an average of more than 52 incidents of insider fraud annually. Traditional security controls, such as application logging, are often powerless in these situations. When malicious insiders with legitimate reasons for accessing applications, querying databases, and changing system configurations alter, destroy or obfuscate records, institutions are often left powerless to determine what actually happened. As a result, a detailed audit trail of user access to sensitive corporate data has become a necessity for protecting your corporate brand and information assets. It is also required by an increasing number of government regulations and especially privacy regulations.
While many organizations maintain access logs most are insufficient due to the following 3 limitations:
The logs are missing record and field-level data, and focus solely on a given transaction.
The reality is that most existing logs only contain information at the transaction level, such as: Which users accessed which transaction at what time? In these cases, critical information is still missing. Vital questions such as “Which specific records and fields did the user access?’ and “What did the user do with the data?” go unanswered.
Main existing systems fail to log read-only actions, leaving gaps in the records.
Most existing logs only record update activities. This leaves critical information about what was viewed, queried or simply accessed out of audit trail entirely. In these cases, there is often no record of the times information was accessed without being changed. This information is extremely important for preventing and investigating information leakage and data theft. Another area where this absence of information reveals significant gaps is in demonstrating access to private or privileged information.
If available, logs represent an incomplete view of activities that is often “hidden” across multiple systems and difficult to correlate.
The reality is that many logs are maintained in disparate systems or applications that don’t “talk” to each other. This makes it difficult to find and correlate relevant information—or respond quickly to an audit request. This reality often aids the malicious insider in obscuring their activity.
Legacy systems that were developed a decade or two ago and even many newer systems were not designed for collecting detailed data access logs. Altering logging capabilities or introducing a logging mechanism to these applications frequently required the addition of a logging component to each online program. In a large enterprise, this can add up to tens of thousands of lines of code. An activity of this type can easily translate into hundreds of programmer-months, system performance overhead and additional maintenance. With all the additional time, money and effort such an activity would require, the costs of upgrading a traditional logging system to support modern audit needs with a detailed audit trail quickly becomes exorbitant.
What if you could:
Stop scrambling to piece together incomplete data on scattered enterprise systems in order to create a complete audit trail?
Know for certain whether your standard operating procedures are being followed?
Gather clear and legally actionable forensic evidence—even weeks or months after the user activity occurred?
Luminet from Attachmate solves these problems and other out-of-the-box without changing any application code and with no overhead on the existing systems or network. By recording and analyzing user activity on the application level, Luminet generates a very detailed audit trail of user access to the corporate applications and data. This audit trail is invaluable for both real-time and post-event investigations. It enables the internal auditor to search, for example, for all the users who accessed a specific account number in a specific timeframe across any application across any platform in the enterprise. The auditor can zoom in on any user session retrieved by the query and replay the user’s actions screen by screen, keystroke by keystroke.
Attachmate offers a product demonstration as the first step in the evaluation of Luminet software. To see how the next generation fraud technology can revolutionize your fraud and audit efforts, click here to contact us. If you would prefer, feel free to call us directly at 1.800.872.2829 and ask for a demonstration today.