|
-----Original Message-----
From: midrange-l-bounces@xxxxxxxxxxxx
[mailto:midrange-l-bounces@xxxxxxxxxxxx] On Behalf Of rob@xxxxxxxxx
Sent: Tuesday, November 25, 2008 10:35 AM
To: Midrange Systems Technical Discussion
Subject: Audit
Boss is asking me to gather data for an IT audit. You know,
I would be hard pressed to find a worse waste of time. As
usual, they want the list of system values. I am sure that
is so they can consider it a ding if we allow a user to have
more than one session. Doesn't matter if they can go to 30
PC's and fire up browsers and look at the data but two 5250
sessions is a concern.
Then they have the usual commands they want to be secured:
STRSEU, UPDDTA that sort of rot. Of course WRKQRY, RUNQRY
QRYFILE..., STRSQL, EDTF are not in the list. And no mention
of WDSC, etc.
And, why be concerned about the special authority of *ALLOBJ
when they don't check one file at all to see if you are using
resource security?
Does it matter if no one has *ALLOBJ yet *public has *all
authority to the list of social security numbers and everyone
has iSeries Access (or ftp, or ...)?
Gee, why don't we tell them that there is no twinax that
leaves the locked door? Based on the above wouldn't that
then constitute a secured system?
Rob Berendt
--
Group Dekko Services, LLC
Dept 01.073
Dock 108
6928N 400E
Kendallville, IN 46755
http://www.dekko.com
--
This is the Midrange Systems Technical Discussion
(MIDRANGE-L) mailing list To post a message email:
MIDRANGE-L@xxxxxxxxxxxx To subscribe, unsubscribe, or change
list options,
visit: http://lists.midrange.com/mailman/listinfo/midrange-l
or email: MIDRANGE-L-request@xxxxxxxxxxxx Before posting,
please take a moment to review the archives at
http://archive.midrange.com/midrange-l.
As an Amazon Associate we earn from qualifying purchases.
This mailing list archive is Copyright 1997-2025 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].
Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.