fhs
Volume 9, Number 7 -- February 17, 2009

Safestone Cracks Down on Excessive Authority with PUP

Published: February 17, 2009

by Alex Woodie

Safestone Technologies last week unveiled a new System i security product aimed at reducing the risk posed by users with excessive authorities. Called Powerful User Passport, or PUP, the new software gives administrators a way to grant users powerful authorities for a short period of time, and then force them back to a user profile with less authority when they have completed the tasks requiring special powers.

"This particular product addresses the problem of powerful users on the System i," says Terry Heath, chief operating officer for Safestone, which is based in the UK and has an office in Seattle, Washington. "Powerful users on the System i are the auditors' number one concern, because if somebody has something like ALLOBJ authority, then they have authority over all objects, which means they are all powerful, almighty, on the System i, and auditors don't like that."

Auditors have good reason to be concerned with excessive use of powerful user profiles in corporate computer systems. For one thing, studies have shown that employees account for anywhere from 50 to 80 percent of computer break-ins, so leaving the server wide open for employees to explore is an invitation for fraud. Another reason for auditors to worry is that companies too often grant too many powerful authorities to too many employees. While it's easier in some cases from a programming or management perspective to give users full access to the System i, it's almost always a bad idea from a security standpoint.

System i administrators and security officers have a dozen or so special authorities to worry about. ALLOBJ is the most powerful, and grants users access to everything on the system. But there are less well known authorities that administrators and programmers occasionally need to make changes to the system, such as Security Admin (SECADM), Network Services (IOSYSCFG), Audit Rights (AUDIT), Hardware Administrator (SERVICE), Backup Operator (SAVESYS), Job Control (JOBCTL), and Spool Control (SPLCTL).

The operative word here is "occasionally." And that's the central idea behind Safestone's new Powerful User Passport.

With PUP, users are provided a user profile that contains the minimum amount of authorities they need on a day-to-day basis. If they have a need for one of the special authorities, they can log in under a different user profile that grants them these authorities. PUP makes this transition seamless.

PUP also provides a time limit for the use of the special authorities. As the time limit nears, the user is flashed a warning on his screen that he will need to log out of the special user profile soon. If the user does not log out in time, PUP can take action to end any active jobs gracefully.

Auditing is turned on while the user is working with the special authorities, providing a way for administrators to replay the user's session after the fact, if required. In addition to ensuring that none of the powerful user's deeds go untracked while he or she is logged in with PUP, it also protects the user from accusations of wrongdoing, because there's a full audit trail.

If there is a need to go back through the audit trail, Safestone provides tools to make it easier. "We have some really good filtering in the product itself," Heath says. "So we can say, 'Just give me all the key commands that the user performed, such as copy or delete. Or just give me the specific files they touched, like payroll or customer files.'"

One of the most compelling uses of the product will be to monitor user activities after hours or on weekends, says Simon Bott, Safestone product manager. "Say you have a system support guy making sure your RPG applications are running on your production machine," he says. "Those guys typically will say 'I must have ALLOBJ authority, because you want me to support it on off hours and weekends.' Clearly in the eyes of the auditor, that's a risky policy to have.

"So what the Powerful User Passport can do is allow a management or compliance or auditing officer to make a decision, to say to the development guy, 'I will trust you to use that special authority extensively if and when you need it. I'll grant you into the system temporarily to have that access.' You can actually remove the ALLOJB authority from that user profile. He then has a command that he can use in his environment, which will then give him temporary access."

When a user swaps into a powerful user profile with PUP, he can be prompted to provide an explanation for the need for special authorities. PUP also ties into ticketing and help desk applications, and alerts the administrator that a user with special authority is on the AS/400.

Using a third-party vendor such as Safestone also eliminates any potential conflict of interest issues for programmers, Heath says. "Some companies have recognized this problem, and what they've done is they've written their own routines to be able to protect against it," he says. "But what's happened more recently is auditors are beginning to switch onto this thing and the idea that there's a solution that's been written by somebody within the firewall, and that doesn't protect the business, because that person could have written a logic bomb or a backdoor or any kind of thing in there. As we say, who polices the policemen?"

Powerful User Passport is the latest addition to Safestone's DetectIT suite of i OS security solutions, which is now composed of nine core modules. The software is available now, and ranges in price from $2,000 to $22,000. For more information, visit www.safestone.com.


RELATED STORIES

Safestone Gives i Security Officers Greater Control

Safestone Re-emerges with New Corporate Identity, i OS Security Tools

Safestone Emerges with New Security Products

SafeStone Delivers New Adapter for Password and Provisioning Suite

SafeStone Announces New Resource Provisioning Software



                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
LANSA

Help your company survive the
economic downturn and attain success.

                                           Learn how organizations achieved
                                           dramatic results with
Business Mashups:

                                                25% productivity improvement across
                                                 12 key business processes

                                                90% cost savings vs. rewriting apps
                                                And much more . . .

Mashup Your Business Apps with LANSA

FREE WEBINAR and other good stuff!


Editor: Alex Woodie
Contributing Editors: Dan Burger, Joe Hertvik,
Shannon O'Donnell, Timothy Prickett Morgan
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

Vision Solutions:  Learn About Data Integration for Business Intelligence
COMMON:  Join us at the 2009 annual meeting and expo, April 26-30, Reno, Nevada
WMCPA:  24rd Annual Spring Technical Conference, April 1 & 2, 2009, Delavan, WI


 

IT Jungle Store Top Book Picks

Easy Steps to Internet Programming for AS/400, iSeries, and System i: List Price, $49.95
Getting Started with PHP for i5/OS: List Price, $59.95
The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
The System i Pocket RPG & RPG IV Guide: List Price, $69.95
The iSeries Pocket Database Guide: List Price, $59.00
The iSeries Pocket Developers' Guide: List Price, $59.00
The iSeries Pocket SQL Guide: List Price, $59.00
The iSeries Pocket Query Guide: List Price, $49.00
The iSeries Pocket WebFacing Primer: List Price, $39.00
Migrating to WebSphere Express for iSeries: List Price, $49.00
iSeries Express Web Implementer's Guide: List Price, $59.00
Getting Started with WebSphere Development Studio for iSeries: List Price, $79.95
Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
Getting Started with WebSphere Express for iSeries: List Price, $49.00
WebFacing Application Design and Development Guide: List Price, $55.00
Can the AS/400 Survive IBM?: List Price, $49.00
The All-Everything Machine: List Price, $29.95
Chip Wars: List Price, $29.95


 
The Four Hundred
The AS/400 Made Off with the Money

IBM's Dynamic Infrastructure Announcement Blitz

Sugar in the YiPs Sandbox

Mad Dog 21/21: Biting The Handout

Soltis Tapped for Vision Solutions Advisory Group and Road Shows

Four Hundred Guru
A Bevy of BIFs: Look Up to %LookUp

Treasury Of New DB2 6.1 Features, Part 1: Query Enhancements

Admin Alert: Time Gobbling Tasks for a System Upgrade

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

System i PTF Guide
February 14, 2009: Volume 11, Number 7

February 7, 2009: Volume 11, Number 6

January 31, 2009: Volume 11, Number 5

January 24, 2009: Volume 11, Number 4

January 17, 2009: Volume 11, Number 3

January 10, 2009: Volume 11, Number 2

TPM at The Register
Red Hat and Microsoft ink virt interoperability deal

Intel's future Xeons to share sockets

Rackable stomached $31.3m loss in 2008

VIA spins mini-mobo disk array

Cray thanks Uncle Sam for juiced revenues

Cuba crafts extra-communist Linux distro

IBM lobs biz software at Amazon cloud

Dell punts green gear with 0% interest

Unisys tastes recession red ink

Intel confirms Nehalem Xeons imminent

Intel to spend $7bn to upgrade US factories

Europe gets first petaflops super

Red Hat updates real-time Linux

Deconstructing and rebuilding IBM's server sales

THIS ISSUE SPONSORED BY:

LANSA
PowerTech
Maximum Availability
HiT Software
Twin Data


Printer Friendly Version


TABLE OF CONTENTS
Safestone Cracks Down on Excessive Authority with PUP

Infor Carves Out a Dedicated System i Division

FMS Solutions Finds mrc's m-Power a Good Fit

looksoftware Developing Cloud Connector for i OS

Three New Log Apps Rolled Out By LogLogic

News Briefs and Product Shorts:

SAP Says Infor's Customers and Partners Are Migrating to SAP . . . Centerfield Passes a Stimulus Package for i OS Applications . . . Inovis Launches a 'Facebook' for the Supply Chain . . . BOSaNOVA Taps Leostream for Virtualization Partnership . . . Stay-Linked Partners with Pragma for SSH Server . . .

Four Hundred Stuff

BACK ISSUES




 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2009 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement