Preparing for a High-profile Termination

Steve Martinson <smartfamily2003-/[email protected]> Tue, 3 Jul 2007 09:30:55 -0700 (PDT)
Newsgroups gmane.comp.systems.as400.security
Message-ID <[email protected]>
Situation:
 
High-profile, knowledgeable staff member soon to be terminated (employment, not by Ahh-nold); has "keys to the kingdom" for both the System i and the network; likely knows passwords for many service and/or utility profiles on the iSeries.
 
Requirement:
 
Prior to term date, analyze system for vulnerabilities associated with a position like the one described above and prepare a task list that will address the situation both before and after the termination.
 
Areas to be reviewed include system values, network attributes (exit points too), directory entries, SST, job descriptions, subsystem routing entries, all user and group profile parameters and their implications, authorities to libraries, directory (WRKLNK) authorities, etc.
 
Can anyone think of anything else that could be a critical hole that should be reviewed/covered?
 
Best regards and TIA,
 
Steven W. Martinson, CISSP, CISM
Sheshunoff Management Services, LP.
Senior Consultant - Technology & Risk Management
2801 Via Fortuna, Suite 600 | Austin, TX 78746
Direct: 281.758.2429 | Mobile: 512.779.2630
e.Mail: [email protected]


       
____________________________________________________________________________________
Choose the right car based on your needs.  Check out Yahoo! Autos new Car Finder tool.
http://autos.yahoo.com/carfinder/
_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400) mailing list
To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.