IBM i Security Audit Process
An audit that produces a report nobody reads is wasted effort. The process matters as much as the checklist.
Define Scope and Cadence Before You Start
Decide upfront whether this is a full-scope audit (every architecture layer, every powerful profile, every exit point) or a targeted audit (one specific control, one specific compliance framework requirement). Full-scope audits belong on an annual or semi-annual cadence; targeted audits of high-risk areas (powerful profile activity, *PUBLIC authority drift) can run monthly or quarterly with much less effort per cycle.
Audit Steps
1. Pull Current State
System values, authority collection results, exit point registrations, and QAUDJRN configuration, captured fresh, not from the last audit.
2. Compare Against Baseline
Diff current state against your last audit or your documented hardening baseline to catch drift, not just absolute gaps.
3. Interview, Don't Just Scan
Ask administrators why a powerful profile exists or why an exit point rule was relaxed; some findings only surface through conversation.
4. Score and Prioritize Findings
Rank by exposure and remediation effort, the same way as in the assessment process, so findings translate into an actual work plan.
5. Assign Owners and Deadlines
A finding without an owner and a date does not get fixed. This is the step most audits skip.
6. Re-Verify at the Next Cycle
Confirm prior findings were actually remediated before closing them, not just noted as 'in progress' indefinitely.
Compliance Framework Alignment
If the audit needs to satisfy PCI DSS, SOX, or a similar framework, map each control requirement to the specific IBM i mechanism that satisfies it (e.g., PCI DSS access-control requirements map to object authority and *PUBLIC settings; PCI DSS logging requirements map to QAUDJRN configuration and retention) before the audit starts, so the audit produces evidence in the format an assessor expects rather than raw system output that needs translation afterward.
Journal-based compliance monitoring products can generate audit-ready reports directly from QAUDJRN and object-level journal data, which materially reduces the manual evidence-gathering burden of a recurring audit. See the Software Guide for vendor options in this category.