Mainframe Visibility
.

100% Visibility into All Mainframe Database Activity

Tracking the details of who is accessing data and what is done with the data is now required for compliance with regulations such as Sarbanes Oxley (SOX) and the Payment Card Industry Data Security Standard (PCI-DSS).  IBM Guardium for z/OS is the only database auditing solution that provides 100% visibility into mainframe database activity without impacting business processes.

IBM Guardium for z/OS uses proven z/OS monitoring technology which is integrated with the Guardium enterprise architecture.  This allows you to easily identify access to sensitive data and unauthorized changes by privileged users on System Z from a centralized management point.

IBM Guardium for z/OS detects and immediately reports anomalous behavior and activities that violate corporate policies, generating policy-based actions such as security alerts.  The system provides the data protection you need and enables you to meet regulatory requirements—without sacrificing performance and availability.

Key Features

  • Captures all critical operations, including activity from:
    • SELECTS, DML and DDL
    • DB2 utilities
    • Access grants and revokes
  • Monitors and audits all activity for privileged users, mainframe-resident applications and network clients
  • All analysis, reporting and storage of log data is performed off-mainframe
  • Provides fine-grained audit information
  • Integrates with the Guardium architecture to provide a unified solution for both mainframe and distributed database environments



Enlarge Image

IBM Guardium for z/OS uses a proven, mainframe-resident software probe called S-TAP for z/OS to capture all database activities by privileged users, mainframe-resident applications and network clients (connecting via JDBC or DB2 Connect, for example).  The S-TAP for z/OS probe operates at the DBMS level.  Both mainframe and distributed environments can be managed from a single centralized console; in addition, all audit data is automatically aggregated and normalized into a single centralized repository.