[BBLISA] Guidelines for giving full root access to DBAs
Michael Tiernan
michael.tiernan at gmail.com
Sun Aug 20 11:11:58 EDT 2006
On 8/20/06, Sharon Nagao <sharon.nagao at gmail.com> wrote:
> I was informed last week by my manager that the DBAs is to have full root
> access to all Dev and Test servers in our environment.
As quick as a bunny in hunting season I'd get tripwire running on the
systems. You can skip doing MD5 sums for most of the files (it
consumes a lot of time and cycles) just a reality check of
permissions, ownership, change/modify/access times, and simple
checksum will leave you lots of breadcrumbs to follow.
Second thing to do is to figure out how to get them to feel the pain
when something goes wrong (not that we're expecting this to
happen.....) Maybe devise a plan where any changes they've made have
to be reviewed and either approved or challenged. If it's challenged,
they have to account for the reaons or switch it back. Make sure they
get paged for errors too. ;)
--
<< MCT >> Michael C Tiernan.
Is God a performance artist?
EGO hack vivo quod ago accido.
More information about the bblisa
mailing list