Sun Microsystems today introduced an audit system dubbed Java System Identity Auditor, designed to allow firms to monitor employees' network identity and system access activities.
The audit policy engine within the software is designed to scan critical applications, flag audit policy violations and evaluate violation criteria, such as segregation of duties, unauthorised access changes, and erroneous access privileges.
The offering has been developed to help firms comply with legislative regulations, such as Sarbanes-Oxley, which demand that companies must be able to report on, and manage who has access to, critical information systems such as financial applications or medical records.
The compliance regulations also oblige companies to provide data on historical access privileges, in addition to secure, auditable evidence that internal controls are in place.
According to Sun, Identity Auditor can help automate the evaluation and enforcement of a company's internal identity and access controls.
"Companies are spending substantial sums of money to hire and manage external consultants to perform auditing and compliance tasks for identity management activities," said Roberta Witty, a research vice president at Gartner.
"To answer the question of 'who has access to what?', and to prove it, companies need a secure, automated analysis and reporting solution that is cost-effective and comprehensive in its capabilities, including the scope of supported platforms and applications as well as role conflict analysis."
Sara Gates, vice president of identity management at Sun, added that Identity Auditor can help firms identify controls across critical enterprise applications and provide audit trail reporting.
Dubbed Barnard's star B, newly discovered planet is believed to be rocky
Also, what's a USB stick?
Gravitational waves become extremely weak by the time they reach the Earth and require highly sensitive equipment for detection
The reactor topped out at 100 million° C