If the FSM user services are stopped (accidentally/deliberately) will the system administrator be able to access the files without being monitored by FSM?
3 years ago
Originally Published: 2008-07-17
Article Number
000066722
Applies To
RSA File Security Manager
RSA File Security Manager (FSM)
Issue
If the FSM user services are stopped (accidentally/deliberately), will the system administrator be able to access the files without being monitored by FSM?
FSM in an ?audit only mode?.
Customer deploys the FSM adapter in an Audit Only mode for ?c:\data? folder(This means that monitored files are not encrypted)
The customer wants to monitor all file access activity including system administrators.
Resolution
No,  the system administrator will not be able to access the files without being monitored by FSM.  An ?Access Denied? error message will be presented when FSM monitored files are accessed by any user. This ensures that system administrators cannot bypass FSM auditing.