Slashdot Mirror


User: vod1

vod1's activity in the archive.

Stories
0
Comments
1
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 1

  1. Re:BS on Insider Threat · · Score: 1

    'IT' needs access to do its job. We need *total* access to all systems and data or we cant be effective and might as well not goto work.

    In a perfect security world you don't need total access. I work for a very large corporation which have seperate network, firewall, Unix, and database groups. If you are in the Unix group you don't need access to the data in the database. If you are a firewall person you don't need an account on the Unix server. There is also an audit department that makes sure all the accounts on the application belong to legit people who need it.

    I agree having so many different people managing a single system makes troubleshooting much harder but having a check and balance system in place takes total access out of the hands of few people. The idea is that to do any real damage you would actually need the help from multiple people in different groups, making it harder to hide a conspiracy.