As other have saied, we also use special profile dedicated to job
scheduling. And those profile can not signon.
As for the access to the JS by an admin/operator, I am surprised that
your auditor have a problem with that. If the JS is for invoicing and
the operator has access to the JS, you have separation of duty (unless
the operatior also work in invoicing). IF the person in charge of
invoicing had access to the JS, then you could have a separation of duty
issu.
Anyway, managing the JS is part of an admin job. If an admin can not
access a JS, who can?
Denis Robitaille
Directeur services technique TI
819 363 6130
SUPPORT
Jour (EST) Daytime : 819-363-6134
En-dehors des heures (EST) After hour : 819-363-6158
Network Status : 819-363-6157
"Burns, Bryan" <Bryan_Burns@xxxxxxxxxxxx> 2008-08-13 09:55 >>>
What's your policy on the user profile to be used for scheduled jobs?
In the past we've all used our own profiles but that's not the best
approach because the user might leave the company. In fact, our
invoicing job was running under a user's name long after he left the
company until I finally changed it.
Furthermore, auditors don't think that I - the operator / administrator
- should even have access to the JS due to the need for "separation of
duties". Well, management said they'll accept the risk on that one and
put detective controls in place.
And by the way, thanks to everyone who replied to my post about QSECOFR
user profiles - they were very helpful.
Bryan Burns
iSeries Specialist
ECHO, Incorporated
Lake Zurich, Illinois
As an Amazon Associate we earn from qualifying purchases.