• The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
Menu
  • The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
  • Safestone Cracks Down on Excessive Authority with PUP

    February 17, 2009 Alex Woodie

    Safestone Technologies last week unveiled a new System i security product aimed at reducing the risk posed by users with excessive authorities. Called Powerful User Passport, or PUP, the new software gives administrators a way to grant users powerful authorities for a short period of time, and then force them back to a user profile with less authority when they have completed the tasks requiring special powers.

    “This particular product addresses the problem of powerful users on the System i,” says Terry Heath, chief operating officer for Safestone, which is based in the UK and has an office in Seattle, Washington. “Powerful users on the System i are the auditors’ number one concern, because if somebody has something like ALLOBJ authority, then they have authority over all objects, which means they are all powerful, almighty, on the System i, and auditors don’t like that.”

    Auditors have good reason to be concerned with excessive use of powerful user profiles in corporate computer systems. For one thing, studies have shown that employees account for anywhere from 50 to 80 percent of computer break-ins, so leaving the server wide open for employees to explore is an invitation for fraud. Another reason for auditors to worry is that companies too often grant too many powerful authorities to too many employees. While it’s easier in some cases from a programming or management perspective to give users full access to the System i, it’s almost always a bad idea from a security standpoint.

    System i administrators and security officers have a dozen or so special authorities to worry about. ALLOBJ is the most powerful, and grants users access to everything on the system. But there are less well known authorities that administrators and programmers occasionally need to make changes to the system, such as Security Admin (SECADM), Network Services (IOSYSCFG), Audit Rights (AUDIT), Hardware Administrator (SERVICE), Backup Operator (SAVESYS), Job Control (JOBCTL), and Spool Control (SPLCTL).

    The operative word here is “occasionally.” And that’s the central idea behind Safestone’s new Powerful User Passport.

    With PUP, users are provided a user profile that contains the minimum amount of authorities they need on a day-to-day basis. If they have a need for one of the special authorities, they can log in under a different user profile that grants them these authorities. PUP makes this transition seamless.

    PUP also provides a time limit for the use of the special authorities. As the time limit nears, the user is flashed a warning on his screen that he will need to log out of the special user profile soon. If the user does not log out in time, PUP can take action to end any active jobs gracefully.

    Auditing is turned on while the user is working with the special authorities, providing a way for administrators to replay the user’s session after the fact, if required. In addition to ensuring that none of the powerful user’s deeds go untracked while he or she is logged in with PUP, it also protects the user from accusations of wrongdoing, because there’s a full audit trail.

    If there is a need to go back through the audit trail, Safestone provides tools to make it easier. “We have some really good filtering in the product itself,” Heath says. “So we can say, ‘Just give me all the key commands that the user performed, such as copy or delete. Or just give me the specific files they touched, like payroll or customer files.'”

    One of the most compelling uses of the product will be to monitor user activities after hours or on weekends, says Simon Bott, Safestone product manager. “Say you have a system support guy making sure your RPG applications are running on your production machine,” he says. “Those guys typically will say ‘I must have ALLOBJ authority, because you want me to support it on off hours and weekends.’ Clearly in the eyes of the auditor, that’s a risky policy to have.

    “So what the Powerful User Passport can do is allow a management or compliance or auditing officer to make a decision, to say to the development guy, ‘I will trust you to use that special authority extensively if and when you need it. I’ll grant you into the system temporarily to have that access.’ You can actually remove the ALLOJB authority from that user profile. He then has a command that he can use in his environment, which will then give him temporary access.”

    When a user swaps into a powerful user profile with PUP, he can be prompted to provide an explanation for the need for special authorities. PUP also ties into ticketing and help desk applications, and alerts the administrator that a user with special authority is on the AS/400.

    Using a third-party vendor such as Safestone also eliminates any potential conflict of interest issues for programmers, Heath says. “Some companies have recognized this problem, and what they’ve done is they’ve written their own routines to be able to protect against it,” he says. “But what’s happened more recently is auditors are beginning to switch onto this thing and the idea that there’s a solution that’s been written by somebody within the firewall, and that doesn’t protect the business, because that person could have written a logic bomb or a backdoor or any kind of thing in there. As we say, who polices the policemen?”

    Powerful User Passport is the latest addition to Safestone’s DetectIT suite of i OS security solutions, which is now composed of nine core modules. The software is available now, and ranges in price from $2,000 to $22,000. For more information, visit www.safestone.com.

    RELATED STORIES

    Safestone Gives i Security Officers Greater Control

    Safestone Re-emerges with New Corporate Identity, i OS Security Tools

    Safestone Emerges with New Security Products

    SafeStone Delivers New Adapter for Password and Provisioning Suite

    SafeStone Announces New Resource Provisioning Software



                         Post this story to del.icio.us
                   Post this story to Digg
        Post this story to Slashdot

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Tags:

    Sponsored by
    Midrange Dynamics North America

    Git up to speed with MDChange!

    Git can be lightning-fast when dealing with just a few hundred items in a repository. But when dealing with tens of thousands of items, transaction wait times can take minutes.

    MDChange offers an elegant solution that enables you to work efficiently any size Git repository while making your Git experience seamless and highly responsive.

    Learn more.

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Sponsored Links

    Vision Solutions:  Learn About Data Integration for Business Intelligence
    COMMON:  Join us at the 2009 annual meeting and expo, April 26-30, Reno, Nevada
    WMCPA:  24rd Annual Spring Technical Conference, April 1 & 2, 2009, Delavan, WI

    IT Jungle Store Top Book Picks

    Easy Steps to Internet Programming for AS/400, iSeries, and System i: List Price, $49.95
    Getting Started with PHP for i5/OS: List Price, $59.95
    The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
    The System i Pocket RPG & RPG IV Guide: List Price, $69.95
    The iSeries Pocket Database Guide: List Price, $59.00
    The iSeries Pocket Developers' Guide: List Price, $59.00
    The iSeries Pocket SQL Guide: List Price, $59.00
    The iSeries Pocket Query Guide: List Price, $49.00
    The iSeries Pocket WebFacing Primer: List Price, $39.00
    Migrating to WebSphere Express for iSeries: List Price, $49.00
    iSeries Express Web Implementer's Guide: List Price, $59.00
    Getting Started with WebSphere Development Studio for iSeries: List Price, $79.95
    Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
    Getting Started with WebSphere Express for iSeries: List Price, $49.00
    WebFacing Application Design and Development Guide: List Price, $55.00
    Can the AS/400 Survive IBM?: List Price, $49.00
    The All-Everything Machine: List Price, $29.95
    Chip Wars: List Price, $29.95

    SaaS to Get a Bump Up from the Down Economy? A Bevy of BIFs: Getting a Date is Easy with %Date

    Leave a Reply Cancel reply

Volume 9, Number 7 -- February 17, 2009
THIS ISSUE SPONSORED BY:

LANSA
PowerTech
Maximum Availability
HiT Software
Twin Data

Table of Contents

  • Safestone Cracks Down on Excessive Authority with PUP
  • Infor Carves Out a Dedicated System i Division
  • FMS Solutions Finds mrc’s m-Power a Good Fit
  • looksoftware Developing Cloud Connector for i OS
  • Three New Log Apps Rolled Out By LogLogic
  • SAP Says Infor’s Customers and Partners Are Migrating to SAP
  • Centerfield Passes a Stimulus Package for i OS Applications
  • Inovis Launches a ‘Facebook’ for the Supply Chain
  • BOSaNOVA Taps Leostream for Virtualization Partnership
  • Stay-Linked Partners with Pragma for SSH Server

Content archive

  • The Four Hundred
  • Four Hundred Stuff
  • Four Hundred Guru

Recent Posts

  • Public Preview For Watson Code Assistant for i Available Soon
  • COMMON Youth Movement Continues at POWERUp 2025
  • IBM Preserves Memory Investments Across Power10 And Power11
  • Eradani Uses AI For New EDI And API Service
  • Picking Apart IBM’s $150 Billion In US Manufacturing And R&D
  • FAX/400 And CICS For i Are Dead. What Will IBM Kill Next?
  • Fresche Overhauls X-Analysis With Web UI, AI Smarts
  • Is It Time To Add The Rust Programming Language To IBM i?
  • Is IBM Going To Raise Prices On Power10 Expert Care?
  • IBM i PTF Guide, Volume 27, Number 20

Subscribe

To get news from IT Jungle sent to your inbox every week, subscribe to our newsletter.

Pages

  • About Us
  • Contact
  • Contributors
  • Four Hundred Monitor
  • IBM i PTF Guide
  • Media Kit
  • Subscribe

Search

Copyright © 2025 IT Jungle