IdExchange 1.9.1

Generating Audit Reports

The reporting module will consolidate both IDMS and CMS system reports to provide a way to generate reports for use by auditors and other third parties. 


Report objective

Steps

1

Successful and unsuccessful attempts to assume a role – The operating system and applications record: date and time of attempted login, username asserted at time of attempted login, and success or failure indication, are logged.

Go to Reports, Event Logging

Select the date range

Select IDMS Activity and CMS Logon Activity

Sort on OprAuth (Login for IDMS)

Sort on CMS: Logon SSL (Login activity for CMS)


 

2

All security-relevant data that is entered in the system – the system records the identity of the local operator performing local data entry so that the accepted data can be associated with the operator in the audit log.

Go to Reports, Event Logging

Select the date range

Select CMS Credential Activity

Sort on WriteRequest

 

For Identity Proofing activities.

Go to queues

Generate report

Sort on REQUESTS, IDACQUIRED

3

All security-relevant messages that are received by the system - date and time, digital signature/authentication mechanism, and message are logged.

Go to Reports, Event Logging

Select the date range

Select IDMS Activity and CMS Logon Activity

Sort on OprAuth (Login for IDMS)

Sort on CMS: Logon SSL (Login activity for CMS)

 

4

All successful and unsuccessful requests for confidential and security-relevant information - date and time of attempted access, username or identity asserted at time of attempt, record of success or failure logging.

Go to Reports, Event Logging

Select the date range

Select IDMS Activity and CMS Logon Activity

Sort on OprAuth (Login for IDMS)

Sort on CMS: Logon SSL (Login activity for CMS

5

Whenever a component generates a Key (not mandatory for single session or one-time use symmetric Keys) – CMS system records all significant events related to CMS operations, including Key Generation.

Go to Reports, Event Logging

Select the date range

Select CMS Credential Activity

Sort on ProcessCredential

 

Go to reports, Certificates

Click Generate Report

Click Certificate Issuance Date

 

6

All Certificate requests – All Certificate requests including: date and time of request, transistion type (request, activate), Operator ID, Completion Status Code, delivered certificate, and device ID or logged.

Go to Reports, Event Logging

Select the date range

Select CMS Credential Activity

Sort on ProcessCredential

 

Go to reports, Certificates

Click Generate Report

Sort on Certificate Issuance Date

 

7

All Certificate Revocation requests – All Certificate Revocation requests including: Date and time of Revocation, type (revoke), Operator ID, and Completion Status.

Go to Reports, Event Logging

Select the date range

Select CMS Credential Activity

In the search field, enter REVOKE

  image2018-10-2_10-13-28.png

Go to reports, Certificates

Click Generate Report

In the search field, enter REVOKE

image2018-10-2_10-13-48.png

 

8

The approval or rejection of a Certificate status change request - identity of equipment operator who initiated the request, message contents, message source, destination, and success or failure indication are logged.

Go to Reports, Event Logging

Select the date range

Select CMS Credential Activity

In the search field, enter REVOKE

image2018-10-2_10-14-47.png

In the search field, enter WriteRequest

image2018-10-2_10-15-14.png

 

Go to reports, Certificates

Click Generate Report

In the search field, enter REVOKE

image2018-10-2_10-13-48.png

 Sort on Certificate Issuance Date

 

 

9

Logon attempts to PKI Application - CMS and RA applications access – date and time of event, type of event, identity of user accessing the system, and success or failure indication are logged.

Go to Reports, Event Logging

Select the date range

Select IDMS Activity and CMS Logon Activity

Sort on OprAuth (Login for IDMS)

Sort on CMS: Logon SSL (Login activity for CMS)