H06.24 Release Version Update Compendium

to a user on the OBJECTTYPE USER access control list allows the user to delete any user on
the system, including Super.Super. There is no change to the CREATE and OWNER permissions.
The Safeguard primary audit records will contain a blank SubjectProgramName field for
events related to authorization requests originating from a remote system. For audit events
generated by a local requestor, the SubjectProgramName will continue to contain the program
file name of the requestor process.
The authorization SEEP message interface is enhanced to include the CPU and PIN of unnamed
requestor processes for process stop operations.
Migration Considerations
When migrating from a pre-H06.24 RVU to the H06.24 RVU, if any of the password quality
attributes is set to ON and PASSWORD-MIN-QUALITY-REQUIRED = 0,
PASSWORD-MIN-QUALITY-REQUIRED will be automatically set to 1 after the migration.
The SubjectProgramName field in the audit report will be blank for remote authorization
requests.
Fallback Considerations
After a fallback from the H06.24 to a pre-H06.24 RVU, Safeguard will not reset the value of
the PASSWORD-MIN-QUALITY-REQUIRED attribute to zero even if all the other password
quality attributes are disabled and re-enabled. The attribute value will remain unchanged.
After a fallback to a pre-H06.24 RVU, the new permissions W and P will be displayed in a
SAFECOM INFO OBJECTTYPE USER command. However, the Safeguard software will ignore
these permissions and not consider them while evaluating access to user records.
XYGATE Merged Audit (XMA)
XYGATE Merged Audit now supports the ArcSight ESM and ArcSight Logger products, the core
components of the ArcSight Security Information and Event Management (SIEM) platform. As of
H06.24, XYGATE Merged Audit users can now feed audit and security event data to these ArcSight
products, allowing NonStop applications and subsystems to be represented at the enterprise level
within the ArcSight SIEM solution. XYGATE Merged Audit supports events from EMS, Safeguard,
the XYGATE suite, BASE24, and the Telco HLR application, among many others. These events are
filtered and normalised by XMA, before being sent to the ArcSight SIEM. Usage of an external
SIEM device such as ArcSight can assist customers in meeting certain regulations, such as PCI DSS.
For a detailed explanation of the XYGATE Merged Audit functionality for ArcSight, please see the
XYGATE Merged Audit Reference Manual.
Migration Considerations
XYGATE Merged Audit users must install the ArcSight-specific log adapter into their XMA
environment, via the TACL macro provided. A parser override must also be installed in the ArcSight
environment see the ArcSight documentation for more information.
Fallback Considerations
None.
XYGATE Merged Audit (XMA) 15