Re: STRSRVJOB and database journal entries

hs-Jsmql6Mm5bsaF16iPYe0/[email protected]
Newsgroups gmane.comp.systems.as400.security
Message-ID <[email protected]>
I have several customers (who have own development department)
which do a really extensive auditing of all programmers which do
not have no special rights on production boxes. Most of them
in the distribution or finance, as reasoned by the problem
discussed in this thread.

For some of them the audit journal is copied to a special 
machine and reviewed by trained personnel; especially the
profiles of the programmers and their CL commands.

In consequence, most auditing is for getting the responsibility...

-h 

-----Original Message-----
From: Wilt, Charles [mailto:CWilt-GqJsjaCkv4dWk0Htik3J/[email protected]] 

I've never heard of any auditors who don't recommend preventing
programmers from having such access to the production box. You if chose
to allow such access then you are choosing to allow such access.
_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400) mailing list
To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.