Journal Receiver Retention for SOX...

"Turnidge, Dave" <DTurnidge-jXHaHu7tDRvNHyFk3Yt2uVaTQe2KTcn/@public.gmane.org>
Newsgroups gmane.comp.systems.as400.security
Message-ID <8A4F55A988C94B40B668BADA133C5CE40B89AD44@mn-msp-exchange.OldRepublicTitle.com>
Per the current understanding of requirements put forward by auditors,
we need to analyze changes and actions that are made/taken by users
outside of the actual production applications. That is, changes made by
command from the command line, etc. We then need to retain this data
(journal receivers) for SEVEN years.
 
There are a couple of issues that I would like to have your thoughts on:
 
1) I got bit last week after having set up an "automatic" analysis,
because one of the Journal files became MASSIVE. One of the steps in my
"automatic" methodology is to dump journal receivers to a data file so I
can run those records against an SQL statement to report on those items
that are out of the range that has been set up. What happened was that
disk filled up. 
 
Is there a way to determine that you are about to do something stupid -
like run out of disk - so you can stop it?
 
2) As a part of my retention routine, I have a tape that just sits in
our development system, and I continue adding save files containing
receivers from all our systems. This is not exactly ... safe ... because
if something happened that destroyed that tape, we wouldn't have backup.
I suppose we could back up just a weeks worth of information, but by the
time we got to SEVEN years, we would probably own the storage company...
 
So, how can I backup what will be massive amounts of data, over a LONG
period of time, and still have the data safe?
 
TIA for any input,

Dave 
612-371-1163 

 
_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400) mailing list
To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.