Re: Auditing changes...By developers



A couple of questions come to mind:

1) Do the developers need the ability to modify the data outside the application?
2) If so, how are they logging in? Do they know the single username/password the application is using?

As Sue posted, a server side trace will show when data is being modified because you can capture the statements. However, getting past the non-repudiation hurdle (being able to deny you did it) is hard to do unless they are logging in with an account whose password only they know and they aren't using shared accounts of any sort.

K. Brian Kelley, brian underscore kelley at sqlpass dot org
http://www.truthsolutions.com/

What is the best way to go to track changes by developers that are
privy to db usernames and passwords?

Not all application users have domain accounts, so we can't use
trusted connections. Instead, we have a single username that the
application (we only have one) uses to perform its work.

We have auditing at the internal application level...Now we need a way
to determine if any of the four developers are possibly manipulating
data.

I briefly looked at application roles, but considering that you can
run sp_setapprole from the QA, that doesn't seem worthwhile.

How is everyone else doing it? Our auditors assure us it is being
done...

Don't you love SOX?

Thanks!

Joseph



.



Relevant Pages

  • Re: How to limit access to production data from non-production code?
    ... would create a situation where one person would have multiple accounts ... then in the ACL indicating which identifier will have access or not. ... Developers never have access to Test or Production environments, ...
    (comp.os.vms)
  • Re: ChangeFSI on Iyonix
    ... The problem is the developers of Prophet did that, ... Richard doesn't want an accounts package written from ... install SAP and the price of the software was around £5m and the price ...
    (comp.sys.acorn.apps)
  • centralizing account mgmt? is it worth doing?
    ... one developer has 15 different UNIX accounts. ... Since my primary goal in life is to make developers' lives easier;) I figure ... In addition to Directory Servers, are there any ...
    (SunManagers)
  • User ID Management
    ... I have a number of developers who *absolutely must have* access to our ... production systems ~60 Suns all on Solaris 8. ... file), I guess management got tired of developers accidentally changing, ... Accounts for 50+ individuals who only need permission *to look at ...
    (SunManagers)