Re: Interesting discussion on ServerFault regarding an idiotic auditor ...

Douglas Handy <[email protected]> Wed, 27 Jul 2011 22:20:44 -0400
Newsgroups gmane.comp.systems.as400.security
Message-ID <CAP8V2sz+ODu+d+4LE3Eb1CjZ46FG8BfTkWtj8Xi7Wa1VgahqUQ@mail.gmail.com>
Jim,

I would think that kind of request is a hacker seeing how stupid a security
> manager can be..
>

It is either that, or an attempt to determine if the security manager can be
"socially engineered" and persuaded to give up information he shouldn't.  It
at least has a small chance of really being part of what they are testing.

But I give it much higher chances of being a hacker, and not really even
from the alleged audit firm.

I give it a near zero chance of being a serious auditor who is serious about
requesting the information.  What probably troubles me the most is this
security manager would even consider trying to fake some data to hand over,
instead of steadfastly refusing to comply and informing higher ups and the
legal beagles.

Doug
_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400) mailing list
To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.