Safeguard Audit Service Manual (G06.24+, H06.03+)
Specifying Auditing
Safeguard Audit Service Manual—520480-014
2-9
Auditing Attempts to Manage Protection Records
•
Attempting to delete a protection record with the DELETE command
If this event is audited, one primary audit record and one secondary audit record
are written to the current audit file. The secondary record contains the image of the
protection record that was deleted or that the user attempted to delete. For user
and alias records, two secondary records are written. See the following note.
The AUDIT-MANAGE attributes are:
specifies the conditions under which successful attempts to manage this protection
record are recorded in the current audit file.
specifies the conditions under which unsuccessful attempts to manage this protection
record are recorded in the current audit file.
The audit-spec variable for AUDIT-MANAGE-PASS and AUDIT-MANAGE-FAIL can
be any one of these four values:
ALL
All attempts to manage this protection record are recorded in the current audit file.
LOCAL
Only local attempts to manage this protection record are recorded in the current
audit file. (A local attempt is made by a user logged on to this system.)
REMOTE
Only remote attempts to manage this protection record are recorded in the current
audit file. (A remote attempt is made by a network user logged on to a remote
system. A network user's attempt to access a protection record is considered
remote regardless of whether the network user is running SAFECOM on the
remote system or on the local system.)
NONE
No attempts to manage this protection record are recorded in the current audit file.
NONE is the default value for both AUDIT-MANAGE-PASS and AUDIT-MANAGE-
FAIL.
Note. For every secondary record containing the image of a user or alias authentication
record, two additional secondary subrecords are written containing extensions to the
authentication record. The
ZSFG-DDL-USER-SUBRECEXT extension subrecord contains
attributes introduced with the D30 product version of the Safeguard subsystem. The
ZSFG-DDL-USER-SUBRECEXT-1 extension subrecord contains attributes introduced with
the G06.27 product version of Safeguard.
AUDIT-MANAGE-PASS audit-spec
AUDIT-MANAGE-FAIL audit-spec