Re: Requested opinions on Access.

Margles <[email protected]>
Newsgroups gmane.comp.security.intrusions
Message-ID <[email protected]>
installing and running a program such as crack
_without-explicit-authorization_  is usually grounds for being
fired...  even if you are Security, which a DBA usually is not.

in my experience, understanding of security, paying attention to
timely patching, proper securing of accounts (including admin
accounts), good passwords, and other issues were all things that the
DBAs did not handle appropriately but complained about.  luckily they
did not have admin rights over their workstations...

it came down to upper management support for proper separation of
duties, and respect for the folks responsible for security in the
different areas.

mas

On Wed, 10 Nov 2004 07:41:37 -0800, Wilson, Mark <[email protected]> wrote:
> Ladies and Gentlemen;
> 
> I have an issue with our Data Base Admins (DBA's) wanting the root passwords for their workstations.  We had just recently a DBA run a crack against a shadow file and move the shadow file from one of the Unix machines to a PC.
> 
> We staff separate Systems Administrators that normally admin these workstations, and I have a "symbiotic" relation on security issues with our SA's and trust them to perform necessary updates.
> 
> Obvious issues aside, I would really like to hear about policies and issues that others have in relation to DBA's having root access.
> These DBA's support our Oracle Financials. (ehhh shiver up my spine) that hold all our customer financial information.
> 
> I would really appreciate responses to this since it has become a very touchy issue and I'm getting stuck in the middle being the Security person.
> 
> Thanks.
> 
> Mark Wilson
> Communications Analyst / IT Security
> Eastern Municipal Water District
> 2270 Trumble Rd.
> Perris Ca.  92572
> 951.928.3777.4544
> www.emwd.org
> 
> _______________________________________________
> Intrusions mailing list
> [email protected]
> http://www.dshield.org/mailman/listinfo/intrusions
>
_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.