I would think that kind of request is a hacker seeing how stupid a security
manager can be..
It is either that, or an attempt to determine if the security manager can be
"socially engineered" and persuaded to give up information he shouldn't. It
at least has a small chance of really being part of what they are testing.
But I give it much higher chances of being a hacker, and not really even
from the alleged audit firm.
I give it a near zero chance of being a serious auditor who is serious about
requesting the information. What probably troubles me the most is this
security manager would even consider trying to fake some data to hand over,
instead of steadfastly refusing to comply and informing higher ups and the
This is the Security Administration on the AS400 / iSeries (Security400) mailing list
To post a message email: Security400@xxxxxxxxxxxx
To subscribe, unsubscribe, or change list options,
or email: Security400-request@xxxxxxxxxxxx
Before posting, please take a moment to review the archives
As an Amazon Associate we earn from qualifying purchases.
Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.