fhs
Volume 7, Number 16 -- April 24, 2007

PowerTech Tools Build Trust By Decreasing Authority

Published: April 24, 2007

by Alex Woodie

It's 7 p.m., and all your users are supposed to be logged off the system, but do you know where your security officer is? While you trust your security officer to hold the keys to the i5/OS kingdom, today's regulatory environment simply doesn't permit all-powerful users to traverse corporate IT systems unseen and unmonitored. A new release of PowerTech Group's AuthorityBroker gives i5/OS shops the capability to monitor the monitors, and get back into the good graces of the auditors.

AuthorityBroker helps i5/OS and OS/400 shops lessen the need for users to run with profiles granting them special authorities, such as All Object (ALLOBJ), Spool Control (SPLCTL), and Job Control-System Operator (JOBCTL). While these special authorities at times are necessary to accomplish given tasks on iSeries and System i servers--such as loading a new program, initiating a system save, or configuring network access--they are overkill for day-to-day usage, and pose a security risk to organizations.

AuthorityBroker decreases the security risk and gets iSeries shops on the track to regulatory compliance by setting up separate user profiles that users can adopt for short periods of time. When a user needs a special authority to accomplish a task, they can go into AuthorityBroker and swap into a "switch" profile, which temporarily gives them the special authority. In this way, users don't need the special authorities in their everyday profile, which lessens security risks. It also helps implement separation of duties, which is necessary for SOX compliance.

With version 3.1, PowerTech has made it easier for organizations to integrate AuthorityBroker into their existing environments, and to initiate other business processes when a profile swap or release occurs. The new integration points enable a customer to run a program of their choice immediately before or after a profile swap is executed. Programming skills are not necessary, but can be utilized, and a recompile is required. Sample code is provided to get users started.

The customization offers numerous benefits. For example, the new capability could be used to associate a library list with a powerful user profile when a swap or release is executed, giving a programmer access to the objects he needs to get his job done while logged on using the powerful user profile. Alternatively, the functionality could be used to change an accounting code when a swap is performed, keeping billable hours in line with actual job duties performed.

The integration points could also be used to automatically distribute reports detailing the activities of users when they're logged in as powerful users, says John Earl, PowerTech's chief technology officer.

"This allows them to get notifications that I've become QSECOFR, and while John was QSECOFR, here's exactly what he did," Earl says. "The big story is, everything I do now is done under the light of day. The security officer is the most knowledgeable and powerful user, but nobody knows what they're doing, and this is why auditors have a problem."

Too many OS/400 and i5/OS shops have too many users with powerful authorities, Earl says. "PowerTech's recently released 'State of System i' study showed that the average number of user profiles with *ALLOBJ authority on a system i server is 82," he says. "Companies can fix this exposure with Authority Broker."

The new integration points could also be used to verify that a valid call ticket has been implemented correctly, or to require a manager's approval before allowing a swap to continue, according to PowerTech. Better tracking of AuthorityBroker use was started last year when PowerTech unveiled the new emergency access "FireCall" feature with version 3.0, which was aimed at empowering helpdesk personnel to grant higher authority levels.

Version 3.1 also brings new "job spawn" tracking capability. In the past, it could be difficult to attribute certain batch jobs, or jobs started under Q shell, to the user and the user profile responsible for starting the job, Earl says. With this release, AuthorityBroker can more accurately track these types of jobs.

AuthorityBroker puts controls in place for the eight special authorities in OS/400 and i5/OS, including Security Admin (SECADM), Network Services (IOSYSCFG), Audit Rights (AUDIT), Hardware Administrator (SERVICE), Backup Operator (SAVESYS), JOBCTL, SPLCTL, and the big one, ALLOBJ.

AuthorityBroker is fully logged and tracks all switches through an audit trail. The software also generates reports on switch activity, and can be set up to automatically send e-mail notifications when users swap into their powerful "switch" profile.

AuthorityBroker supports OS/400 V4R4 and later versions. Pricing is tier-based and ranges from $2,700 to $15,000. For more information, visit www.powertechgroup.com.

RELATED STORIES

PowerTech Adds 'FireCall' to Authority Control Product

PowerTech's AuthorityBroker to be Distributed with New Copies of i5/OS

New PowerTech Product Cracks Down on Special Authorities



                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
BYTWARE

Enhance your System i for free!

In honor of its 20th year serving theSystem i community,
Bytware is giving away 20 free licenses of PeekPlus,
the user monitoring, security enhancement, and
help desk tool that started it all!

Just license Messenger or StandGuard Network Security
and you will be entered into a drawing for a free license.

Offer expires May 31, 2007,
so get started today!

Call us at 800.932.5557 or
visit us online for more information!


Editor: Alex Woodie
Contributing Editors: Dan Burger, Joe Hertvik,
Shannon O'Donnell, Timothy Prickett Morgan
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

New Generation Software:  Leading provider of iSeries BI and financial management software
Vision Solutions:  The first new HA release from the newly merged Vision and iTera companies
LASERTEC USA:  Fully integrate MICR check printing with your existing application


IT Jungle Store Top Book Picks

The System i Pocket RPG & RPG IV Guide: List Price, $69.95
The iSeries Pocket Database Guide: List Price, $59.00
The iSeries Pocket Developers' Guide: List Price, $59.00
The iSeries Pocket SQL Guide: List Price, $59.00
The iSeries Pocket Query Guide: List Price, $49.00
The iSeries Pocket WebFacing Primer: List Price, $39.00
Migrating to WebSphere Express for iSeries: List Price, $49.00
iSeries Express Web Implementer's Guide: List Price, $59.00
Getting Started with WebSphere Development Studio for iSeries: List Price, $79.95
Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
Getting Started with WebSphere Express for iSeries: List Price, $49.00
WebFacing Application Design and Development Guide: List Price, $55.00
Can the AS/400 Survive IBM?: List Price, $49.00
The All-Everything Machine: List Price, $29.95
Chip Wars: List Price, $29.95

 

The Four Hundred
Power6: Later in 2007 Rather than Sooner?

Slowing U.S. Sales Hurt IBM's First Quarter

Reader Feedback on User-Priced System i Boxes

As I See It: Induced Labor

The Linux Beacon
Canonical Updates Ubuntu Linux with 7.04 Release

Intel Details Future 45 Nanometer Chip Plans from Beijing

Dell, IBM Push Power-Saving Servers

As I See It: The Legacy

Big Iron
Slowing U.S. Sales Hurt IBM's First Quarter

Top Mainframe Stories From Around the Web

Chats, Webinars, Seminars, Shows, and Other Happenings

Four Hundred Guru
Calling SQL Functions Directly From a High Level Language Program

My Favorite Keyboard Shortcuts for RSE

Two Ways to Audit Your Backup Strategy

System i PTF Guide
April 14, 2007: Volume 9, Number 15

April 7, 2007: Volume 9, Number 14

March 31, 2007: Volume 9, Number 13

March 24, 2007: Volume 9, Number 12

March 17, 2007: Volume 9, Number 11

March 10, 2007: Volume 9, Number 10

The Windows Observer
'Viridian' Beta Delayed. Is Longhorn Next?

Windows Server DNS Flaw Being Exploited

Dell, IBM Push Power-Saving Servers

Marathon Makes Virtualization Fault Tolerant with v-Available

The Unix Guardian
Fujitsu, Sun Deliver Joint Sparc Enterprise Server Line

Power6: Later in 2007 Rather than Sooner?

Slowing U.S. Sales Hurt IBM's First Quarter

As I See It: Disorderly Conduct

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

THIS ISSUE SPONSORED BY:

Bytware
Quadrant Software
Seagull Software
VAULT400
Affirmative Computer



TABLE OF CONTENTS
PowerTech Tools Build Trust By Decreasing Authority

IBM Expects Speedier Portal Projects

BSafe Introduces Cross-Platform Auditing

CCSS Addresses SOX Requirements in QMessage Monitor

News Briefs and Product Shorts:


Curl Re-Emerges at Web 2.0 . . . Lawson Signs Five Companies to M3 Contracts . . . Magic Develops iBOLT for SAP R/3, mySAP . . . Jupiter Taps MobileHWY for Mobile Building Permit Program . . . Reporting Tool Works with i5/OS Trucking Software . . . Help/Systems Issues Another Update for Robot/SCHEDULE . . .

Four Hundred Stuff

BACK ISSUES





 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2008 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement