IBM i Security and MFA Software

What evidence do we need for compliance reviews or cyber insurance?

Most reviews eventually ask for proof, not policy language. That usually means current access reviews, MFA coverage, privileged account inventories, audit logs, alert history, backup and recovery evidence, and documentation that shows how exceptions are approved and tracked.

Answer

Insurance underwriters in particular have gotten specific in the last few renewal cycles. It is no longer enough to say the environment is protected; carriers increasingly want dated screenshots or exportable reports showing MFA enforcement on remote access, a current list of profiles with *ALLOBJ or *SECADM authority, and evidence that backups include an offline or immutable copy that ransomware cannot reach through a compromised network account. Buyers should ask candidate vendors for a sample compliance report before signing anything, not after the first audit cycle exposes a gap.

The exception-handling piece trips up more environments than the core controls do. Every real IBM i shop has legitimate exceptions, a vendor support account with elevated authority, a batch job that needs to bypass MFA, a temporary grant during a system upgrade, and reviewers expect to see that these exceptions are time-boxed, approved by someone other than the requester, and automatically flagged for removal. Software that logs the exception at the moment it is granted, rather than relying on someone remembering to document it afterward, turns an audit conversation from a scramble into a five-minute report pull. That difference alone can shorten a compliance review or an insurance renewal by weeks.

Back to IBM i Security and MFA Software