PCI Compliance
Posted in 2007
Topics: Triggers, Constraints & Referential Integrity, Versions, Editions & End-of-Life
Has anyone written "select" triggers for IDS 7.31? We need to log everyone who accesses certain tables, and the select triggers are not availble in version 7.31.
I would suggest using onaudit in that case.
This may be an obvious question, but why not upgrade the database engine?
----- Original Message ----
From: KATE TOMCHIK <kate@iiug.org>
To: ids@iiug.org
Sent: Tuesday, February 13, 2007 12:35:17 PM
Subject: PCI Compliance [8402]
Has anyone written "select" triggers for IDS 7.31? We need to log everyone who
accesses certain tables, and the select triggers are not availble in version
7.31.
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
On 2/13/07, KATE TOMCHIK <kate@iiug.org> wrote:
> Has anyone written "select" triggers for IDS 7.31? We need to log everyone
who
> accesses certain tables, and the select triggers are not availble in version
> 7.31.
SELECT triggers are trivial to avoid if you don't want to be tracked,
so you c annot use them for auditing...Hmmm, I should probably add a
note about that to my auditing presentations.
SELECT * FROM InterestingTable INTO TEMP x WITH NO LOG;
SELECT * FROM x;
Oh, you mean you wanted to know that I'd read everything from InterestingTable?
--
Jonathan Leffler #include <disclaimer.h>
Email: jleffler@earthlink.net, jleffler@us.ibm.com
Guardian of DBD::Informix v2005.02 -- http://dbi.perl.org/
NB: Please do not use this email for correspondence - I don't read it
every week, even.