Home > AS/400 Tips > iSeries security tips > iSeries security officer's New Year's resolutions
iSeries 400 Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

ISERIES SECURITY TIPS

iSeries security officer's New Year's resolutions


Rich Loeber
01.09.2006
Rating: -4.38- (out of 5)


iSeries news and advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Many people, myself included, take this time of year for a little introspection. We try to see where we have problems or weaknesses and then contemplate methods and strategies to make changes. If we're serious, we'll sit down and make a list of things to do in the new year. As the security officer for your i5-iSeries-AS/400 shop, this is a good opportunity to do just that for your installation and here's my list of some items you should consider.

  • Finally take the plunge and move the security level of your system up at least one level. If you're running at level 20 (shame on you!), move to level 30. If you're at level 30, move to level 40. Take the time to plan the move and use system security auditing to check results before you make the change.


  • Check your system for user profiles with permanent passwords; then change them all. This will, at least, enforce an annual change in these passwords. And, this means your personal password, too!


  • Review the user profiles on your system and look for people who have left the company. Make sure those profiles are disabled and their passwords have been changed to *NONE. If you can do so easily, remove the profiles.


  • Do a full audit of all of the security related system values on your box and make sure they are set up to enforce your company's security policies correctly.


  • More Information
  • Audit your system backup plan and make sure that the tapes are being properly labeled and stored for quick and accurate recovery if needed.


  • In light of recently publicized problems, check on the way your backup tapes are transported to and from your off-site storage facility to make sure they are secure in transit.


  • Dust off your disaster recovery plan and make sure it still works. Bring it up to date, and then schedule an actual test.


  • Review physical security arrangements for your computer room and for all terminals and PCs attached to your system. Do a walk through and actually look at the various work locations. Check for things like passwords on post-it notes and lists of system resources. Spank a few hands (not literally) for violators. Your physical presence in the end-user's environment will go a long way towards reinforcing the importance of security.


  • Resolve to review your system security audit journal on a regular basis. If you don't have it active, turn it on. If you have it turned on but never look at it, develop a review process to check for problem issues.


  • If you don't have network security implemented at the exit-point level on your system, commit to getting this done in the new year. Either write your own exit routines or take a look at one of the many packages available for this important area of system security.


  • If you have other items to add to the list, let me know. My e-mail address is at the end of this tip, and I'd love to hear about your new year's resolutions.

    For me, I'm going to just resolve to loose 20 pounds this year. But then, that was my resolution last year, and I'm weighing in at the same rate this year. At least things didn't get worse. Let's hope that your system security resolutions fare better.

    If you have specific questions about this topic, e-mail me at rich@kisco.com. All e-mail messages will be answered.

    ---------------------------
    About the author: Rich Loeber is president of Kisco Information Systems Inc. in Saranac Lake, N.Y. The company is a provider of various security products for the iSeries market.


    Rate this Tip
    To rate tips, you must be a member of Search400.com.
    Register now to start rating these tips. Log in if you are already a member.




    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



    RELATED CONTENT
    iSeries system and application security
    Developing a security incident response system for System i
    Setting up security for programmers on IBM i
    Blocking AS/400 DB2 users
    Trouble accessing IFS path from Win2k3 server
    Checking in on your IBM i authorization lists
    Strategies for securing IBM i production files
    Changing password security levels and upgrading operating systems on the IBM i
    Determine the value of parameter UPPWEI in the DSPUSRPRF field
    Define journal code value "K"
    Modify content within a journal receiver file

    iSeries security tips
    Developing a security incident response system for System i
    Tracking remote access users on System i
    Setting up security for programmers on IBM i
    Controlling remote access on your IBM i
    Checking in on your IBM i authorization lists
    PCI data security standards and the System i
    Securing the integrated file system on IBM System i
    Contextual security on IBM i: Limit user profile access
    Time for a security checkup for your i
    Security monitoring on IBM i: Watching your super users

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    midrange  (Search400.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary

    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



    iSeries Security - Security Tools, Physical Security and System Security
    HomeNewsTopicsITKnowledge ExchangeTipsBlogsAsk the ExpertsMultimediaWhite PapersProducts
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 1999 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts