Security Basics mailing list archives

Re: Conflict of interests


From: Richard Thomas <austindad () gmail com>
Date: Tue, 5 May 2009 10:37:06 -0500

First, a request.  Please give us a name to use, even if it's false.
To answer your question, we need to know the type of security role you
play.  Is it operational security or more compliance related?
Generally, you should not require either domain admin access or root.
Most IT staff never need this level of access.  If you could provide
us more information regarding the situation and your role, I think we
could offer more useful input.

Richard Thomas

On Mon, May 4, 2009 at 1:16 PM,  <s0h0us () yahoo com> wrote:
As a security guy, not part of the IT department, I require a level of access in order to perform my job. Certain 
types of tools require privileged access in order to work. Like having domain admin access and/or similar privileged 
access for unix and linux systems. Is it reasonable to request this type of access without causing any type of 
conflict of interest that internal auditors might question? I guess audit trails would come in handy here.
Thanks for the feedback.

------------------------------------------------------------------------
This list is sponsored by: InfoSec Institute

Learn all of the latest penetration testing techniques in InfoSec Institute's Ethical Hacking class.
Totally hands-on course with evening Capture The Flag (CTF) exercises, Certified Ethical Hacker and Certified 
Penetration Tester exams, taught by an expert with years of real pen testing experience.

http://www.infosecinstitute.com/courses/ethical_hacking_training.html
------------------------------------------------------------------------



------------------------------------------------------------------------
This list is sponsored by: InfoSec Institute

Learn all of the latest penetration testing techniques in InfoSec Institute's Ethical Hacking class.
Totally hands-on course with evening Capture The Flag (CTF) exercises, Certified Ethical Hacker and Certified 
Penetration Tester exams, taught by an expert with years of real pen testing experience.

http://www.infosecinstitute.com/courses/ethical_hacking_training.html
------------------------------------------------------------------------


Current thread: