Re: STRSRVJOB and database journal entries
hs-Jsmql6Mm5bsaF16iPYe0/[email protected]
| Newsgroups | gmane.comp.systems.as400.security |
|---|---|
| Message-ID | <[email protected]> |
I have several customers (who have own development department) which do a really extensive auditing of all programmers which do not have no special rights on production boxes. Most of them in the distribution or finance, as reasoned by the problem discussed in this thread. For some of them the audit journal is copied to a special machine and reviewed by trained personnel; especially the profiles of the programmers and their CL commands. In consequence, most auditing is for getting the responsibility... -h -----Original Message----- From: Wilt, Charles [mailto:CWilt-GqJsjaCkv4dWk0Htik3J/[email protected]] I've never heard of any auditors who don't recommend preventing programmers from having such access to the production box. You if chose to allow such access then you are choosing to allow such access. _______________________________________________ This is the Security Administration on the AS400 / iSeries (Security400) mailing list To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected] To subscribe, unsubscribe, or change list options, visit: http://lists.midrange.com/mailman/listinfo/security400 or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected] Before posting, please take a moment to review the archives at http://archive.midrange.com/security400.