|
Tim Shepherd <tshepherd@lia.co.za> wrote: >2. We have an authorisation form for users to fill in for >access to our AS400 and various servers. It's a four >page document and doesn't really suit the purpose >as there is no real control over who gets what access >when. Plus the access givers are different depending >on what machine will be accessed. This means that >the forms are dotted around three or four people. How >do other sites control/authorise access to the various >machines. We have to have this for auditing purposes >and is becoming quite a nightmare to administer. I think the paper record with its signatures is vital. However, it is important that the forms are well designed, so revising the design may be your first step. Ideally, everything would be on one form. However, this can slow things down unacceptably if the form has to go round the houses. The important thing is that the forms are controlled at a single point. They come in somewhere, are logged, the authorisations verified, and are then distributed (possibly electronically) to the people who will actually create the profiles. After creation they are ticked up, countersigned and returned to the central point where they are filed. If there's a delay the current location of the form should be traceable. Another key point is that the profiles and their associated authorities are created using standard procedures. This guarantees consistency, allows simple and rapid creation, and allows the task to be carried out by non-technical personnel. The people who actually create the profiles should have a target time for turning round the forms. It should be possible to have the profiles in place with the correct authorities before a new starter arrives at their desk on their first morning. Dave Kahn, ABB Steward Ltd. PS. I'm not responsible for this at ABB Steward, and none of the above should be taken to reflect their procedures. +--- | This is the Midrange System Mailing List! | To submit a new message, send your mail to MIDRANGE-L@midrange.com. | To subscribe to this list send email to MIDRANGE-L-SUB@midrange.com. | To unsubscribe from this list send email to MIDRANGE-L-UNSUB@midrange.com. | Questions should be directed to the list owner/operator: david@midrange.com +---
As an Amazon Associate we earn from qualifying purchases.
This mailing list archive is Copyright 1997-2025 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].
Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.