SQL SOX audit and logging



Hi,

We are currently being audited for SOX compliance. The auditor wants us to
create log that captures all the activities from the DBA in the SA role.
Is there an easy way to generate logs for this audit that can be written to
the system event logs or flat file?
We can cause any performance delays on the SQL server...So I think profiler
might be too much for 24/7/365 logging.
Do you use any third party tool you would suggest for SOX auditing and
logging?

Any help is good!!!

Thanks,


.



Relevant Pages

  • SQL SOX auditing and logging
    ... We are currently being audited for SOX compliance. ... create log that captures all the activities from the DBA in the SA role. ... Is there an easy way to generate logs for this audit that can be written to ... might be too much for 24/7/365 logging. ...
    (microsoft.public.sqlserver.tools)
  • RE: [fw-wiz] Log checking?
    ... tend to evaluate where and what logging is important in a different light. ... I've been happy to analyze a year's worth of firewall denied logs, ... have denied firewall traffic logs or denied logs with any relevant data. ...
    (Firewall-Wizards)
  • Re: Login Errors Seem to indicate we are being hacked?
    ... thing on the box using that authentication package. ... The SMTP or IIS logs should answer everything. ... I'm not familiar with that particular router or its logging capabilities, ...
    (microsoft.public.windows.server.sbs)
  • Re: Logging Best Practice?
    ... a lot depends on who's going to read the logs. ... lookup where the log line originated and look at the program flow. ... I usually implement logging in a way the user can choose the logging level ... Those are ment for checking if the ...
    (comp.programming)
  • [TOOL] The Logging Project
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... of a need for secure, centralized, fault tolerant, real time logging. ... system logs are only part of the package. ... * Message queuing when tunnel is offline (sptc) ...
    (Securiteam)

Quantcast