RE: Requested opinions on Access.
"Williamson, Glenn (MBS)" <[email protected]>
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <3739F6DD3C0271438ECA1C87A2CC7EE6ECF377@cacptoqpmxis001.cac.ad.gov.on.ca> |
Mark, As a security person, the assumption would be to hold the keys to the farm. What I mean is, unless absolutely essential for you SA's to have root access, then there should be no valid reason to turn over access to the root account. I'm not sure what you deal with MAC - DAC but danger always resides, when too many people have root access, not always caused intentionally but if you trust 10 people to lock the door and one forgets, then you are just as able to lose the farm, if you left the keys in the door. Customer Financial Information is key to the subject, who do you want to have access to this, even trusted individuals, unless there is a specific need to know, then they need access to root account, no need to know, would mean they have no need to have access to the root account. (Limit access, except to those who need access to support their function) Those are my personal comments. Regards, Glenn R. Williamson CD, CISSP, GCIA Corporate Security 5th Floor 155 University Av. Toronto, On M5H 3B7 Tel: 416-327-3904 Fax: 416-327-3262 Cell: 905-320-2910 E-mail: [email protected] -----Original Message----- From: Wilson, Mark [mailto:[email protected]] Sent: November 10, 2004 10:42 AM To: [email protected] Subject: [Intrusions] Requested opinions on Access. Ladies and Gentlemen; I have an issue with our Data Base Admins (DBA's) wanting the root passwords for their workstations. We had just recently a DBA run a crack against a shadow file and move the shadow file from one of the Unix machines to a PC. We staff separate Systems Administrators that normally admin these workstations, and I have a "symbiotic" relation on security issues with our SA's and trust them to perform necessary updates. Obvious issues aside, I would really like to hear about policies and issues that others have in relation to DBA's having root access. These DBA's support our Oracle Financials. (ehhh shiver up my spine) that hold all our customer financial information. I would really appreciate responses to this since it has become a very touchy issue and I'm getting stuck in the middle being the Security person. Thanks. Mark Wilson Communications Analyst / IT Security Eastern Municipal Water District 2270 Trumble Rd. Perris Ca. 92572 951.928.3777.4544 www.emwd.org _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions