This article, entitled "11 Steps to an Effective FTP Audit", written by Scott Myers, was published in the Institute of Internal Auditors, Vol. 10, January 10, 2007.
Abstract: Identifying and automating file transfer protocol activities are two of the steps organizations can take to protect sensitive data that is transmitted through this increasingly used technology.
This white paper provides a simple test for ensuring that the activity of your z/OS FTP server and client are being logged in SMF records. It also has detailed instructions for enabling the FTP logging option if you determine that activity is not currently being logged.