IBM AS400 Security Procedures(8)
Auditor(s) Assigned Audit Date
Workpaper
Audit Objectives and Procedures Ref. By
________________________________________________________________________________________________________
K.5 Objects
Objectives: To ensure that appropriate access authority is defined at
the object level in order to protect specific production data files and programs from unauthorized access.
Object security establishes security at the specific object level. It is used when different objects require different protection requirements. The client may choose to protect specific sensitive objects at the object level if their inherent risk is high or if library level protection is not used. It can also be used as an exception to the general authorization rules.
Procedures:
K.5.1 Select a sample of sensitive production objects (data files or source
programs) and print their specific object authorities:
DSPOBJAUT OBJ(library/file) OBJTYPE(*FILE) (for files), and
DSPOBJAUT OBJ(library/program) OBJTYPE (*PGM) (for programs).
K.5.2 Ensure that only authorized users or groups may access or use the
sensitive objects.
K.5.3 Review administration and authorization procedures for granting
access to significant objects.
E&Y recommendation: Since assignment of object authorities to specific objects is tedious, specific object authority should only be defined to handle exceptions; otherwise, the default public authority should be used.
SYSTEM SECURITY K/PROG
35
Page 17 of 22
Auditor(s) Assigned Audit Date
Workpaper
Audit Objectives and Procedures Ref. By
________________________________________________________________________________________________________
K.6 System Utilities
Objective: To ensure that powerful system utilities are adequately
restricted from unauthorized access and use.
The following are powerful system utilities:
SST System Service Tools DST Dedicates Service Tools DFU Data File Utility SEU Source Entry Utility SDA Screen Design Aid PDM Programming Development Manager QUERY Query Language
Procedures:
K.6.1 Determine who has access to the above utilities:
? DSPOBJAUT OBJ(QSYS/STRDFU) OBJTYPE (*CMD).
? DSPOBJAUT OBJ(QSYS/STRSEU) OBJTYPE (*CMD).
? DSPOBJAUT OBJ(QSYS/STRSDA) OBJTYPE (*CMD).
? DSPOBJAUT OBJ(QSYS/STRPDM) OBJTYPE (*CMD).
? DSPOBJAUT OBJ(QSYS/STRQRY) OBJTYPE (*CMD).
Only authorized programmers should have access to these utilities.
E&Y recommendation: *PUBLIC access should be set to *EXCLUDE, not *USE.
SYSTEM SECURITY K/PROG
36
Page 18 of 22
Auditor(s) Assigned Audit Date
Workpaper
Audit Objectives and Procedures Ref. By
________________________________________________________________________________________________________
K.7 System Commands
Objective: To ensure that powerful system commands are adequately
restricted from unauthorized use.
The following are powerful system commands:
* CRTUSRPRF Create User Profile * CHGUSRPRF Change User Profile * DLTUSRPRF Delete User Profile * RSTUSRPRF Restore User Profile
?? CHGDSTPWD Change Dedicated Service Tool Password
RSTAUT Restore Authority # STRSST System Service Tools ~ CRTAUTHLR Create Authority Holder ? DLTAUTHLR Delete Authority Holder ?? SAVSYS Save the System
~ CHGSYSLIBL Change System Library
CHGSYSVAL Change System Value
* Restricted to the security administrator (QSECADM) and security
officer (QSECOFR) only. PUBLIC access is irrelevant. A user cannot use these commands even if he/she has *ALLOBJ special authority.
# Restricted to the service engineer (OSRV) only. ~ Restricted to the security officer (QSECOFR) only.
? You need the DST security password to change the DST passwords. ? Restricted to *SAVSYS capability holder. ? *PUBLIC should be set to *EXCLUDE.
See the sensitive command object authority matrix.
SYSTEM SECURITY K/PROG
37
Page 19 of 22
Auditor(s) Assigned Audit Date
Workpaper
Audit Objectives and Procedures Ref. By
________________________________________________________________________________________________________
K.7 System Commands - Cont'd
Procedure:
K.7.1 Review the object authority to the above significant security related
commands:
DSPOBJAUT OBJ(QSYS/cmd) OBJTYPE(*CMD).
Ensure that only authorized personnel may use these commands.
E&Y recommendation: Public authority of these commands should be set at *EXCLUDE.
Command source object contains …… 此处隐藏:2035字,全部文档内容请下载后查看。喜欢就下载吧 ……
相关推荐:
- [资格考试]机械振动与噪声学部分答案
- [资格考试]空调工程课后思考题部分整合版
- [资格考试]电信登高模拟试题
- [资格考试]2018年上海市徐汇区中考物理二模试卷(
- [资格考试]坐标转换及方里网的相关问题(椭球体、
- [资格考试]语文教研组活动记录表
- [资格考试]广东省2006年高应变考试试题
- [资格考试]LTE学习总结—后台操作-数据配置步骤很
- [资格考试]北京市医疗美容主诊医师和外籍整形外科
- [资格考试]中学生广播稿400字3篇
- [资格考试]CL800双模站点CDMA主分集RSSI差异过大
- [资格考试]泵与泵站考试复习题
- [资格考试]4个万能和弦搞定尤克里里即兴弹唱(入
- [资格考试]咽喉与经络的关系
- [资格考试]《云南省国家通用语言文字条例》学习心
- [资格考试]标准化第三范式
- [资格考试]GB-50016-2014-建筑设计防火规范2018修
- [资格考试]五年级上册品社复习资料(第二单元)
- [资格考试]2.对XX公司领导班子和班子成员意见建议
- [资格考试]关于市区违法建设情况的调研报告
- 二0一五年下半年经营管理目标考核方案
- 2014年春八年级英语下第三次月考
- 北师大版语文二年级上册第十五单元《松
- 2016国网江苏省电力公司招聘高校毕业生
- 多渠道促家长督导家长共育和谐 - 图文
- 2018 - 2019学年高中数学第2章圆锥曲线
- 竞争比合作更重要( - 辩论准备稿)课
- “案例积淀式”校本研训的实践与探索
- 新闻必须客观vs新闻不必客观一辩稿
- 福师大作业 比较视野下的外国文学
- 新编大学英语第二册1-7单元课文翻译及
- 年产13万吨天然气蛋白项目可行性研究报
- 河南省洛阳市2018届高三第二次统一考试
- 地下车库建筑设计探讨
- 南京大学应用学科教授研究方向汇编
- 2018年八年级物理全册 第6章 第4节 来
- 毕业论文-浅析余华小说的悲悯性 - 以《
- 2019年整理乡镇城乡环境综合治理工作总
- 广西民族大学留学生招生简章越南语版本
- 故宫旧称紫禁城简介