Home | Print | Archive | Blog | Contact
A Quarterly Newsletter for Unisys ClearPath Forward Clients | June 2018

Simplifying Security Reporting with
Locum Software Products

MCP

By Fernando Noguchi, ClearPath Solutions Architect, Unisys

Tight security is a proven, long-standing hallmark of the ClearPath Forward® environment. Even in its default settings, ClearPath Forward security provides ample protection for even the most demanding applications and workloads. And with the complementary Secure Access Control Module (SACM) package, you can benefit from even more security features, such as longer passwords, greater password complexity, and password valid dates.

Nevertheless, reporting on which settings are configured and how these settings contribute to your organization’s overall compliance position can prove challenging – especially as your environment grows in complexity. For instance, quickly showing how many usercodes are configured, and identifying the privileged users among them, can prove daunting.

Easing complex security reports was a key reason why we partnered with Locum Software Services Ltd., a UK-based software provider that makes security-related tools for the ClearPath® MCP operating environment. In particular, the Locum SafeSurvey and Locum SecureAudit products – both part of the comprehensive Locum 360 solution – were built specifically to help you address various security reporting requirements.

With SafeSurvey, you can access reports containing the configuration information auditors typically request. Using SecureAudit, you’ll be able to analyze and report on security violations that are registered in the SUMLOG or SECURITYLOG files the system automatically generates.

And the best news of all: Both products are included in the ClearPath MCP software stack in their “summary” versions. While these provide ample information on their own, there are “detailed” versions of each product that require a separate activation key.

Wondering specifically how these tools could be put to use? Consider these examples…

Identifying Internal Exposures

During a tech demo, a member of our client’s support team knew the organization had done well to protect itself against external threats, like hackers looking for sensitive data, but wasn’t as certain when it came to internal exposure points.

A demo of SecureAudit extracted data showing several security violations. After digging a bit deeper, we isolated the events and identified the root cause as a password mismatch caused by a change in the password used to access a specific MCP network drive. With the help of the demo, it soon became clear that this one issue could impact the integrity of Client Access Services and the overall security of the system.

Tracking Down Privileged Users

We asked a client to predict how many privileged usercodes were present in their Userdatafile. Out of approximately 500, they estimated no more than five or six had privileged status. After generating a quick report in SafeSurvey, it turned out over 100 were designated as “privileged,” “SecAdmin,” or both. Once again, this is an insight the organization would not have easily discovered without the help of the Locum software.