Operations

IBM i Compliance

Almost no compliance framework mentions IBM i. They talk about access control, separation of duties, audit trails, and encryption, and leave the translation to you. That translation is the entire job, and it is why two shops running identical hardware can produce completely different audit outcomes.

Last verified

The Translation Problem

An auditor arrives with a control framework written for a general computing environment. You have a platform with special authorities, adopted authority, library lists, exit points, and a journal receiver model that has no direct equivalent anywhere else. Nothing in the framework tells either of you how those map.

The shops that do well here are not the most secure ones. They are the ones that wrote the mapping down before the auditor showed up. That document, boring as it is, converts a week of discovery into an afternoon of evidence.

What the Main Frameworks Actually Want

Framework Requirements Translated to IBM i

This is a working translation, not legal advice. Your auditor's interpretation of a control is the one that counts, which is exactly why agreeing the mapping with them early is worth the meeting.

FrameworkWhat It Asks ForWhere It Lands on IBM i
SOXControls over financial reporting systems, separation of duties, change management, and evidence that access is restricted and reviewed.Special authority review, adopted authority on financial applications, QAUDJRN change auditing, and a documented profile review cycle.
PCI DSSCardholder data protected at rest and in transit, unique IDs, MFA for access, logging retained, and regular testing.Column-level or field encryption in Db2 for i, TLS on all network access, MFA on sign-on and exit points, QAUDJRN forwarded and retained.
HIPAAAccess controls, audit controls, integrity, and transmission security for protected health information.Object and field-level authority on PHI libraries, audit journaling of read access, and encryption of data leaving the system.
GDPRLawful access to personal data, demonstrable security of processing, and the ability to find and erase records.Knowing which libraries and files hold personal data, authority restrictions on those objects, and a real answer to who read this record.
NIS2Risk management, incident handling, and supply chain security for essential and important entities.Documented assessment cycle, monitored exit-point and audit journal activity, and vendor access controls that are actually enforced.

What Auditors Ask For, Almost Every Time

A List of Profiles With Special Authorities

Specifically *ALLOBJ, *SECADM, *SPLCTL, and *SERVICE, with a business justification for each. The list is easy. The justifications are where it falls apart.

Evidence That Access Is Reviewed

Not that it is correct. That somebody looked, on a schedule, and signed something. A monthly automated report with a reviewer name beats an annual perfect one.

Proof the Audit Journal Is On and Retained

QAUDCTL and QAUDLVL settings, plus retention. If receivers are being deleted at the end of the week, say so before they find it.

Separation of Duties

That the person administering security is not the only person reviewing it. On small IBM i teams this is the hardest control to satisfy honestly.

Change Management on Production Objects

Who can move a program into production, and where that is recorded. Adopted authority and library list handling both come up here.

Password Policy in Force

QPWDLVL, expiry, minimum length, and reuse rules as actually set, not as documented in a policy nobody applied.

Where Compliance Monitoring Software Fits

Compliance monitoring products for IBM i mostly do three things: collect audit journal and exit-point data continuously, run it against a rule set mapped to a framework, and produce reports formatted for someone who does not know what a journal receiver is. That third one sounds trivial and is frequently the reason the software gets bought.

The honest limitation is that these tools report against controls, not against risk. A system can produce a clean compliance dashboard while carrying twenty profiles with *ALLOBJ, because the rule set checked that special authorities were reviewed, not that there were few of them. Compliant and secure overlap. They are not the same set.

Buy it when the reporting burden is real and recurring, when you have multiple frameworks to satisfy at once, or when the audit evidence is currently being assembled by hand each cycle. Do not buy it expecting the findings to shrink. It tells you where you stand more clearly, more often, and in a format somebody else will read.

The Gap Worth Naming

Every recurring industry assessment tells the same story: the average IBM i system passes its audits and still carries default passwords, excessive special authorities, and unguarded exit points. Those two facts sit together comfortably, because the audit checked whether a process existed and the assessment checked what the settings were.

That is not an argument for ignoring compliance. Compliance work is often the only reason IBM i security gets funded at all, and using an audit cycle to finance a genuine cleanup is a reasonable trade. It is an argument for not mistaking the certificate for the outcome.

If you want one thing from this page: write the control mapping down and keep it current. It is the cheapest artefact in the whole compliance process and it does more work than any single product you can buy.

Vendors Covering This Control

Precisely (Assure Security)

Precisely's Assure Security suite is the broadest single-vendor IBM i security platform on the market, spanning multi-factor authentication, encryption, compliance monitoring, and access control in one licensing family. It is the platform we point mid-size and enterprise IBM i shops to first when they need one vendor covering the most ground.

Strengths

  • Widest single-suite coverage: MFA, encryption, exit point control, and compliance monitoring under one console
  • Strong native IBM i journal-based monitoring with real-time SIEM forwarding (Splunk, QRadar, Sentinel)
  • Assure Encryption supports field-level and full-database encryption without application changes in most cases
  • Established install base and long IBM i-specific engineering history (originated from Townsend Security and Syncsort lineage)

Limitations

  • Suite pricing and licensing complexity increases as modules are added; full-suite cost is not the cheapest entry point
  • MFA client coverage for legacy green-screen sessions requires exit-point configuration that takes real implementation time
  • Reporting UI is functional but less modern than some newer point-solution dashboards

Best fit: Mid-size to enterprise IBM i shops that want one vendor for MFA, encryption, and compliance monitoring rather than stitching together point products.

Fortra (Powertech)

Fortra's Powertech line (formerly HelpSystems, formerly PowerTech Group) is the longest-running dedicated IBM i security vendor and still the largest install base by most industry surveys, including its own annual State of IBM i Security Study. Powertech Multi-Factor Authentication, Authority Broker, Exit Point Manager, and Compliance Monitor are each strong standalone products.

Strengths

  • Largest install base among dedicated IBM i security vendors, with the deepest bench of IBM i-specific security expertise
  • Powertech Authority Broker is a mature, well-regarded privileged access / elevated-authority management product
  • Exit Point Manager provides granular network access control across FTP, ODBC, DDM, and remote command exit points
  • Publishes the annual State of IBM i Security Study, a widely cited independent-feeling data source (though vendor-funded)

Limitations

  • Product line grew through acquisition (PowerTech, Bytware, Robot, Vityl) and integration between modules is less unified than Precisely's single suite
  • Some legacy product UIs (Robot Console-adjacent tooling) show their age relative to newer competitors
  • Full stack pricing across MFA, Authority Broker, Exit Point Manager, and Compliance Monitor adds up for smaller shops

Best fit: Shops that specifically need best-in-class privileged access management (Authority Broker) or exit-point network control, and are comfortable managing several point products rather than one suite.

Trinity Guard

Trinity Guard (TGSecure, TGAudit, TGDetect) is a smaller, IBM i-focused vendor built by veterans of the original PowerTech engineering team. Its products are priced aggressively and aimed at shops that want core compliance and threat-detection coverage without enterprise-suite overhead.

Strengths

  • Built by engineers with deep PowerTech/Powertech-era IBM i security experience
  • TGDetect provides real-time threat detection with behavior-based alerting on journal activity
  • Generally lower total cost of ownership than the two larger suite vendors
  • Responsive, IBM i-specialist support with a smaller, more accessible team

Limitations

  • Smaller company footprint means less bench depth for very large, multi-LPAR enterprise rollouts
  • Narrower third-party SIEM and integration ecosystem than Fortra or Precisely
  • Smaller analyst and public case-study presence makes independent verification of claims harder

Best fit: Cost-conscious mid-market shops that want solid compliance monitoring and threat detection without full enterprise-suite pricing.

Cilasoft

Cilasoft is a France-based IBM i security vendor best known for QJRN/400 (journal-based auditing and compliance) and its anti-ransomware detection module. It has a long track record in European IBM i shops and growing presence elsewhere.

Strengths

  • QJRN/400 is a mature, well-regarded journal auditing and reporting engine
  • Anti-ransomware module specifically watches for IFS-side encryption behavior originating from network shares, a real and growing IBM i attack vector
  • Strong compliance reporting templates for European regulatory frameworks (GDPR-adjacent controls)

Limitations

  • Smaller North American market presence and partner network than Fortra, Precisely, or Raz-Lee
  • Product line is narrower (auditing and anti-ransomware) rather than a full security suite
  • English-language documentation and support resources are less extensive than French-language resources

Best fit: IBM i shops, especially in Europe, prioritizing journal-based audit reporting and IFS ransomware detection specifically.