Re: Preparing for a High-profile Termination
"Ross Hartford" <[email protected]> Tue, 3 Jul 2007 11:48:37 -0500
| Newsgroups | gmane.comp.systems.as400.security |
|---|---|
| Message-ID | <[email protected]> |
External servers that connect to the i5 that may use their user id and password Robot or other job schedule entries that may be setup to use their profile. Ross -----Original Message----- From: security400-bounces-Zwy7GipZuJhWk0Htik3J/[email protected] [mailto:security400-bounces-Zwy7GipZuJhWk0Htik3J/[email protected]] On Behalf Of Jones, John (US) Sent: Tuesday, July 03, 2007 11:43 AM To: Security Administration on the AS400 / iSeries Subject: Re: [Security400] Preparing for a High-profile Termination Job scheduler entries. FTP scripts & INI files in the IFS (hard-coded IDs). Shares on other systems. Owned objects. SAV* authority. System distribution directory. Dev/Test systems in addition to production. HMC ID (both for the HMC & for ASMI). 3582 tape library RMU ID. VPN & other network device access. -- John A. Jones, CISSP Senior Analyst, Global Information Security Jones Lang LaSalle, Inc. tel: +1-630-455-2787 fax: +1-312-601-1782 john.jones-4kQQZ61tH+/[email protected] -----Original Message----- From: security400-bounces-Zwy7GipZuJhWk0Htik3J/[email protected] [mailto:security400-bounces-Zwy7GipZuJhWk0Htik3J/[email protected]] On Behalf Of Steve Martinson Sent: Tuesday, July 03, 2007 11:31 AM To: Security Forum Subject: [Security400] Preparing for a High-profile Termination Situation: High-profile, knowledgeable staff member soon to be terminated (employment, not by Ahh-nold); has "keys to the kingdom" for both the System i and the network; likely knows passwords for many service and/or utility profiles on the iSeries. Requirement: Prior to term date, analyze system for vulnerabilities associated with a position like the one described above and prepare a task list that will address the situation both before and after the termination. Areas to be reviewed include system values, network attributes (exit points too), directory entries, SST, job descriptions, subsystem routing entries, all user and group profile parameters and their implications, authorities to libraries, directory (WRKLNK) authorities, etc. Can anyone think of anything else that could be a critical hole that should be reviewed/covered? Best regards and TIA, Steven W. Martinson, CISSP, CISM Sheshunoff Management Services, LP. Senior Consultant - Technology & Risk Management 2801 Via Fortuna, Suite 600 | Austin, TX 78746 Direct: 281.758.2429 | Mobile: 512.779.2630 e.Mail: [email protected] ________________________________________________________________________ ____________ Choose the right car based on your needs. Check out Yahoo! Autos new Car Finder tool. http://autos.yahoo.com/carfinder/ _______________________________________________ This is the Security Administration on the AS400 / iSeries (Security400) mailing list To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected] To subscribe, unsubscribe, or change list options, visit: http://lists.midrange.com/mailman/listinfo/security400 or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected] Before posting, please take a moment to review the archives at http://archive.midrange.com/security400. This email is for the use of the intended recipient(s) only. If you have received this email in error, please notify the sender immediately and then delete it. If you are not the intended recipient, you must not keep, use, disclose, copy or distribute this email without the author's prior permission. We have taken precautions to minimize the risk of transmitting software viruses, but we advise you to carry out your own virus checks on any attachment to this message. We cannot accept liability for any loss or damage caused by software viruses. The information contained in this communication may be confidential and may be subject to the attorney-client privilege. If you are the intended recipient and you do not wish to receive similar electronic messages from us in the future then please respond to the sender to this effect. _______________________________________________ This is the Security Administration on the AS400 / iSeries (Security400) mailing list To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected] To subscribe, unsubscribe, or change list options, visit: http://lists.midrange.com/mailman/listinfo/security400 or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected] Before posting, please take a moment to review the archives at http://archive.midrange.com/security400. _______________________________________________ This is the Security Administration on the AS400 / iSeries (Security400) mailing list To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected] To subscribe, unsubscribe, or change list options, visit: http://lists.midrange.com/mailman/listinfo/security400 or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected] Before posting, please take a moment to review the archives at http://archive.midrange.com/security400.