Re: How can admin not have access to certain shares?
- From: bobm3@xxxxxxxxxxxxxx
- Date: Thu, 28 Feb 2008 07:15:58 -0500
On Tue, 26 Feb 2008 05:57:44 -0500, Leythos <void@xxxxxxxxxxx> wrote:
In article <#ICbOwMdIHA.2404@xxxxxxxxxxxxxxxxxxxx>, anthony@xxxxxxxxxxxx
says...
If you want data to be outside the scope of a domain administrator, it is
fairly obvious that you need to put the data outside the domain.
Auditing the data so that you are alerted when someone accesses it is
different. It is like putting the burglar in charge of setting the alarm.
Anthony
http://www.airdesk.com
Nope, and that would violate most auditing compliance programs out
there.
If you don't trust the administrator then you're screwed to start with.
No matter where you put the data you are doing to have to back it up,
maintain it, administer it, etc.... Someone has to do that, and you have
to trust that person(s).
As the OP of this thread I appreciate all the banter. Most, perhaps
all, of it is valid. The untrusted admin is easy: reassign or
relieve. My experience is that most of the IT people are reliable,
honest and productive. But due to others, primarily large shops like
Enron, the feds are requiring everyone, especially facilities that
have any federal involvement, to be significantly overburdened with
the same rules as these alleged corrupt entities.
I/we trust our admis as he has been instrumental in designing,
defining and managing a reasonably well tuned and managed network
infrastructure. Other departments create and maintain various
documents which, in an effort to control security and access, are
stored on a NAS/SAN within our domain. Some of these docs MIGHT
contain non-public information, and we are being REQUIRED to eliminate
all access to these documents in any way for any purpose by our admin.
And the kicker... we only have ONE admin in a four person shop and the
manager is not allowed to have any system access whatsoever other than
user.
So you see where this original request comes from. But hey, bigger is
better, right?
.
- References:
- How can admin not have access to certain shares?
- From: bobm3
- Re: How can admin not have access to certain shares?
- From: DaveMo
- Re: How can admin not have access to certain shares?
- From: Leythos
- Re: How can admin not have access to certain shares?
- From: DaveMo
- Re: How can admin not have access to certain shares?
- From: Leythos
- Re: How can admin not have access to certain shares?
- From: Anthony [MVP]
- Re: How can admin not have access to certain shares?
- From: Leythos
- How can admin not have access to certain shares?
- Prev by Date: Re: SSL and Remote Desktop
- Next by Date: Re: SSL and Remote Desktop
- Previous by thread: Re: How can admin not have access to certain shares?
- Next by thread: Please recommend good basic Win Server 2003 R2 security book(s)
- Index(es):
Relevant Pages
|
|