Fortinet FortiDB manual Abnormal Use of Service Accounts Report AUS, AUS Report Sample

Page 48

Abnormal Use of Service Accounts Report (AUS)

SOX Report Specifics

Abnormal Use of Service Accounts Report (AUS)

AUS Report Sample

COBIT Objectives and Setup Requirements

Objective

 

FortiDB MA Module

Number(s)

Objective Description

Setup Requirement

 

 

 

DS5.3

Database transactions from unauthorized sources

PM: using the Audit data

 

are tracked and reviewed by IT Management on a

retrieval method

 

weekly basis.

MM: using the Audit data

 

 

 

 

retrieval method

 

 

UBM: Object or User

 

 

policies

 

 

 

Report Body Columns

The following columns are displayed in the report body:

Column

Description

 

 

User ID

The ID of the database user that conducted the flagged activity.

 

 

Terminal Name

The terminal IP address or name.

 

 

Origin Application

The name, or other identifier, for the originating application, if the activity

 

originated from an external application or from an application server.

 

 

# of Actions

The number of actions attempted by the account associated with the User ID.

 

 

Time Stamp

The exact time the flagged activity was conducted.

 

 

 

Note: If you are using an Oracle internal database and use the Limit Rows

 

checkbox in the report's Settings dialog in order to limit the number of report

 

rows, the limit that you specify applies to the number of actions and not to the the

 

number of rows.

 

FortiDB Version 3.2 Utilities User Guide

46

15-32000-81369-20081219

Image 48
Contents Utilities User Guide FortiDB Utilities User Guide TrademarksTable of Contents Index FortiDB MA Utilities Auto Discovery Selecting Addresses for Auto-DiscoverySelecting Non-Standard Ports for Auto-Discovery Results from Auto-DiscoveryMS-SQL Discovered Database Information Populating Connection FormMS-SQL Connection Summary Connection Summary Button Connection Summary OutputRule Chaining Setting Screen Rule ChainingRule Chaining Chaining with Parameterized User-Defined Rules Parameterized User-Defined Rule Flow Diagram General Pudr StepsDisabled Parameter Checkboxes Validating the Pudr before SavingItem Setting for Session Policy Example of Chaining to a PL/SQL-based PudrPolicy Settings for Suspicious Login Time Immediate Table Columns That Could Appear in Alerts Chained-Rule Alerts UBM Session Policy and PudrResulting Killed Session Multiple Source-Rule-Violation Behavior DB ExampleRule Chaining Setting a Report Schedule Setting a Timer-based ScheduleAlert Report Manager Deleting a Previously Set Timer Schedule Setting a Calendar-based ScheduleSetting a Timer-Based Schedule Deleting a Timer ScheduleSetting a Combined Schedule Setting a Randomized IntervalSetting a Calendar-Based Schedule Setting a Randomized IntervalReporting by Time Enabling Email RecipientsSpecifying Report Parameters ARM Reporting by Time ARM Reporting by Time Calendar Pop-upNew Report Setting Screen top New Reports MenuNew Report Setting Screen bottom Saved and Enabled Report Using the Select Checkbox to Affect Multiple ReportsActivating ARM Running and Analyzing ReportsStatus Menu Status Dialog View Reports Dropdown List on Current Reports ScreenCurrent Report Configuration Report Summary ActionChoosing Summary Report Action Summary-Action Output TypesReport Detailed Action LimitationReport Size Archiving Reports Using This Feature Custom ReportsScheduling Custom ReportsTime-only Schedule Settings Daily Schedule Settings Weekly Schedule Settings Monthly Schedule SettingsCustomer and Company Information Report and Template Generation and Management Company Information DialogCustom Reports Main Adding Reports Modifying ReportsAdding a Report Deleting Reports Modifying a ReportDeleting a Report Modifying Report Templates Generating Reports Report ResultTemplates Manager Modifying a Template Generated Html Report Example Report History Report HistoryLicensing and Administration User Administration for Custom Reports and SOX ReportsReports radio button on the User Administration screen Property Purpose Possible Values DefaultProperty Purpose Possible Values Default1 LimitationsSOX Compliance Reports SOX Reports within Custom Reports ManagerGeneral Setup Instructions Reports and AcronymsCommon Report Header Fields Report Name AcronymCobit Objectives and Setup Requirements History of Privilege Changes Report HPCReport Body Columns HPC Report SampleAbnormal or Unauthorized Changes to Data Report AUC AUC Report SampleAbnormal Use of Service Accounts Report AUS AUS Report SampleAbnormal Termination of Database Activity Report ATD ATD Report SampleEnd of Period Adjustments Report EPA Settings Dialog for the EPA ReportEPA Report Sample Case AssumptionsVerification of Audit Settings Report VAS VAS Report SampleLicensing and Administration Archiving ReportsReport Size Verification of Audit Settings Report VAS Index