 




<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Activities of a User in AS/400</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/itanswers/activities-of-a-user-in-as400/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/itanswers/activities-of-a-user-in-as400/</link>
	<description></description>
	<lastBuildDate>Fri, 24 May 2013 15:01:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: dand</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/activities-of-a-user-in-as400/#comment-62047</link>
		<dc:creator>dand</dc:creator>
		<pubDate>Wed, 08 Apr 2009 18:05:42 +0000</pubDate>
		<guid isPermaLink="false">#comment-62047</guid>
		<description><![CDATA[If you have power users, that is users with any special authorities and command line usage, you should turn on user auditing (chgusraud) for those profiles. If you are in a SOX, PCI or HIPPA regulated environment, the audit journal should be dumped regularly for review of command line usage.  If users with command line access have update or existance rights to your production data, you should audit them and restrict there access to data utilities such as DFU, DBU and SQL.

*LIMTCPB *YES limiting users to their authorized menu options is the first line of defense on an iSeries.  Programmers with command line access should be read only to production data.  Everything after that, like auditing user profiles and files, is just mitigating bad security decisions]]></description>
		<content:encoded><![CDATA[<p>If you have power users, that is users with any special authorities and command line usage, you should turn on user auditing (chgusraud) for those profiles. If you are in a SOX, PCI or HIPPA regulated environment, the audit journal should be dumped regularly for review of command line usage.  If users with command line access have update or existance rights to your production data, you should audit them and restrict there access to data utilities such as DFU, DBU and SQL.</p>
<p>*LIMTCPB *YES limiting users to their authorized menu options is the first line of defense on an iSeries.  Programmers with command line access should be read only to production data.  Everything after that, like auditing user profiles and files, is just mitigating bad security decisions</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached
Database Caching 3/10 queries in 0.034 seconds using memcached
Object Caching 266/272 objects using memcached

Served from: itknowledgeexchange.techtarget.com @ 2013-05-24 16:24:07 -->