IBM Champions

 View Only
  • 1.  SMF retention

    Posted Mon October 14, 2024 07:12 AM
    Edited by Andrew McCandless Tue October 15, 2024 04:42 AM

    Hi All,

    I'm sure this question must have been asked many times before, but can I ask it again.

    Is there any guidance anywhere on SMF records, what type of records must be maintained and for how long {does this need to be kept}.

    - UK
    - Finance

    How long the information is retained? 
    How must it be maintained? {Audit proof archive}

    Is there an Audit compliance requirement? {certain data types, for duration}


    I can find lots of information on capturing SMF data and types, I am curious about what data needs to be retained and for how long

    Is there any legal guidance I can read around this?



    ------------------------------
    Andrew McCandless
    ------------------------------



  • 2.  RE: SMF retention

    Posted Tue October 15, 2024 01:02 AM

    Hi!

     Well in the EU we will shortly be getting the DORA coming into effect and then you must store even more stuff for even longer. Back a few years was GDPR of course and before that Sarbanes-Oxley and the rest of the Personal Data audit requiremnets.

    The ROT I use is: save everything about access, updates and select from critical data for as long as you can but a minium of seven years. Same is true for any attempted logons, user id changes (Think SET CURRENT SQLID or Translation here!). All about Roles etc.

    Most of the console messages and any use or abuse of encryption. 

    Basically a huge amount of data. The good news is you can simply offload down to a PC in corner and "leave it there" until an Auditor requests the data..

    just my 0.02



    ------------------------------
    Roy Boxwell
    Senior Software Architect
    Software Engineering GmbH
    Duesseldorf
    +4921196149675
    ------------------------------



  • 3.  RE: SMF retention

    Posted Tue October 15, 2024 04:36 AM

    Hi Roy!

    Thank you for the speedy and helpful response.

    I will bookmark this as this is one of the best takes on SMF usage and retention I have seen.



    ------------------------------
    Andrew McCandless
    ------------------------------



  • 4.  RE: SMF retention

    Posted 9 days ago

    Hi,

    For more than 20 years this same question was brought every year on the systems management plan over the time. In my first position we were storing 5 years of some records from SMF information, but I remember we storing data generated with a feature called SLR. With the decrease of the storage price we kept more info and even more with the facility of storing those records in distributed storage systems, we were just storing many more years that the 5 year figure was keeping extending every exercise. The latest customer I worked for, we were storing 20 years+. You never know. Compliance is good, but as far as we have resources, is never bad to keep more than requested. I think it like an airbag in the car, you want it, you never want to use it, but it is always there. 

    Kind regards

    Diego Rodriguez Bravo



    ------------------------------
    Diego Rodriguez Bravo
    ------------------------------