Audit Installs

Sort:
You are not authorized to post a reply.
Author
Messages
MattD
Veteran Member
Posts: 94
Veteran Member
    We have external auditors review our system yearly. One thing they requested is that we audit changes made to the system weekly (patches, ctps, etc). We would like to automate this process so that we do not manually have to review the install logs. We previously were doing this by sending the install logs via email and then rolling them off, but Lawson recently informed us this is not a good idea, because the install applications may review those logs.

    I am not sure if this is a likely case, but since I am unsure I would like to find a new process.

    Does anyone else roll off the logs or have any suggestions on how to automate auditing the system. I was thinking about writing a script that did a diff of a copy of the file from a week ago and the current file.

    If there are any better ideas I would welcome them.

    Cheers Mates.
    riegerj
    Veteran Member
    Posts: 44
    Veteran Member
      My understanding is that altering the install logs or rolling them off could be bad if you ran into a situation where you needed to roll back a CTP or patch. You would probably realize fairly soon after applying a patch that you need to roll back, but...what if? I also believe that CTPs check the installl log to see what really needs to be applied.

      If it's just a once a year process, couldn't you make a copy of the instal log and just delete everything up to the point you had the year before? We use TripWire software to catch any program modifications and then we had better have the paperwork to support the change for audit. It definitely isn't automated, but it is what has worked for us.
      PZ
      Basic Member
      Posts: 8
      Basic Member
        Hi riegerj,

        We just recently installed Tripwire and would like to use it in the same capacity. Would you be willing to share some background on how you have it configured? Are you monitoring all of the files or specific directories, etc.?

        Thanks in advance.
        You are not authorized to post a reply.