Internal Auditor
As the internal auditor I want to ensure that the IT databases are not compromised by internal fraud or simple mistakes. However, all the systems I have seen are not auditing the database, they are sampling it. As the Auditor I find this completely unacceptable, but the solution is to check every single transaction on it’s way in and on its way out, surely this would put an acceptable load on these databases, cause performance difficulties and anyway I can’t countenance an external process impacting on our live transaction systems, it’s out of the question.
The Cervello Solution - Automate database auditing with Cervello Audit DB
Data auditing helps mitigate the significant business risks associated with requirements for regulatory compliance and the use of corporate data assets, including fraud, failed audits, lost customers, and loss of brand/reputation. Audit DB, an enterprise data auditing solution, mitigates these risks by providing a comprehensive audit trail of critical data activity including data access, data changes, data viewing (who's looking at what data) and changes to database structure. Data auditing augments current security measures by focusing on activity inside the firewall, where the majority of data misuse, intentional or otherwise, occurs. Data auditing provides assurance that data is used only in appropriate ways, in order to meet regulatory requirements, and for data management best practices.
Audit DB provides a trusted, unimpeachable audit trail and supports audit best practices of separation of duty, and separation of audit system. Audit DB audits backdoor access by internal users, even privileged users. So your CFO can confidently attest to integrity of data. With Audit DB they can.
Audit DB is a comprehensive enterprise solution that captures all types of database activity, including data modifications (who changed what data?), database structure (who has changed permissions? Failed login attempts?) and data views (who has looked at what data?)
|
|
Key Risks
From My Point of View
Regulatory Compliance
|