Information Systems:Mini audit of IBM i user authorities (Jan. 2018)
Jump to navigation
Jump to search
A few findings after performing a mini-audit of IBM i object authorities. The audit was done in the context of learning how IBM i authorities worked, for the purpose of properly setting up a new development environment. The specifics will not be exposed here.
- A few active users have *ALLOBJ authority but have password set to *NONE so they cannot log on. However, other users may still be allowed to submit jobs as them.
- There are a few staff members with *ALLOBJ authority that should not have this level of authority, despite their rank in the company.
- There are a few non-staff members with *ALLOBJ authority that look to have been created for temporary purposes but remain enabled.