RE: Requested opinions on Access.

"Williamson, Glenn (MBS)" <[email protected]>
Newsgroups gmane.comp.security.intrusions
Message-ID <3739F6DD3C0271438ECA1C87A2CC7EE6ECF377@cacptoqpmxis001.cac.ad.gov.on.ca>
Mark,

 As a security person, the assumption would be to hold the keys to the farm.
What I mean is, unless absolutely essential for you SA's to have root
access, then there should be no valid reason to turn over access to the root
account. 

 I'm not sure what you deal with MAC - DAC but danger always resides, when
too many people have root access, not always caused intentionally but if you
trust 10 people to lock the door and one forgets, then you are just as able
to lose the farm, if you left the keys in the door. 

 Customer Financial Information is key to the subject, who do you want to
have access to this, even trusted individuals, unless there is a specific
need to know, then they need access to root account, no need to know, would
mean they have no need to have access to the root account. (Limit access,
except to those who need access to support their function)

 Those are my personal comments.

Regards,
 
Glenn R. Williamson CD, CISSP, GCIA
Corporate Security
5th Floor
155 University Av.
Toronto, On M5H 3B7
Tel: 416-327-3904
Fax: 416-327-3262
Cell: 905-320-2910
E-mail: [email protected]



 

-----Original Message-----
From: Wilson, Mark [mailto:[email protected]] 
Sent: November 10, 2004 10:42 AM
To: [email protected]
Subject: [Intrusions] Requested opinions on Access.


Ladies and Gentlemen;

I have an issue with our Data Base Admins (DBA's) wanting the root passwords
for their workstations.  We had just recently a DBA run a crack against a
shadow file and move the shadow file from one of the Unix machines to a PC.

We staff separate Systems Administrators that normally admin these
workstations, and I have a "symbiotic" relation on security issues with our
SA's and trust them to perform necessary updates.

Obvious issues aside, I would really like to hear about policies and issues
that others have in relation to DBA's having root access. These DBA's
support our Oracle Financials. (ehhh shiver up my spine) that hold all our
customer financial information.

I would really appreciate responses to this since it has become a very
touchy issue and I'm getting stuck in the middle being the Security person.

Thanks.



Mark Wilson
Communications Analyst / IT Security
Eastern Municipal Water District
2270 Trumble Rd.
Perris Ca.  92572
951.928.3777.4544
www.emwd.org

_______________________________________________
Intrusions mailing list
[email protected] http://www.dshield.org/mailman/listinfo/intrusions
_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.