Setting Up User Action Auditing

To set up user action auditing, use the Object Classes section on the navigation panel:

NOTE. When roles of the information security administrator and the application administrator are separated, the Object Classes section is available only for the information security administrator.

The security manager can automatically audit operations executed by system subjects and log information about executed operations to the access protocol. The logged operations are divided into general that can be executed with all object types, and specific ones that can be executed only with specific object types. Operation history is maintained for each object type: object changes, permission changes, object deletion. If full history is maintained, object changes by all operations are saved to history.

Select object types

Change object access permissions

Enable or disable auditing

Enable or disable history

NOTE. Changing of permissions and disabling of auditing and history is available for several selected objects.

To apply the specified settings, click the Save button on the toolbar or side panel.

NOTE. If section parameters have been changed, an attempt to go to another section of the security manager or to close it displays a request to apply the changed settings.

Adding Attributes

Set attributes for object classes when the attribute-based access control method is used inn the following order:

See also:

Setting Up System Security Policy | Object Classes | Selecting Auditing and History Operations | Creating Custom Attributes