Join this online user group to communicate across Z Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.
Truist Data Risk Classification: [-Internal-]
Greetings,
I ran an Access Monitory job and added the SIM_VIA in the SORTLIST to Simulate Access. Some of the SIM_VIA came back as NOTHING. Does anyone know what NOTHING means from SIM_VIA. There are cases where an ID accessed the same profile via ID_GROUP and NOTHING.
Thanks in Advanced for your help.
Rgrds,
Willie Crosby
Asst. Vice President
Cybersecurity Senior Engineer
303 Peachtree Center Ave. NE 4th Floor | Atlanta, GA. 30303
Mail Code GA-ATL-0201
Office: 404.575.2963
willie.crosby@truist.com
BB&T and SunTrust are now Truist
Hi Willie,
in fact this is documented here: https://www.ibm.com/docs/en/szs/3.1.0?topic=records-access-field-descriptions#select_list_fields_access_field_descs__SIM_VIASIM_VIAAccess simulation did not use any connect attribute or profile to determine the event result; for example, because the event was for a command that created the profile. NOTHING is also used to report on access by the audit-only ID *BYPASS*.Regards,
------------------------------Tom Zeehandelaarz/OS Security Enablement Specialist - zSecure developerIBM------------------------------
Truist Data Risk Classification: [-Private-]
Thanks Tom....