Mark,

 

We opted not to take away rights from the Administrators and turned on auditing for areas where sensitive data is stored.  We have been kicking around turning on the file system encryption.  We have had to comply with Grahm-Leech-Blyley (GLB) and a California state bill requiring similar security / privacy measures. Hope this is helpful.

 

Thanks,

Raymond


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Creamer, Mark
Sent: Wednesday, June 23, 2004 10:21 AM
To: [EMAIL PROTECTED]
Subject: [ActiveDir] Sarbannes Oxley compliance

 

I’m curious what, if any, changes to everyday administration the folks on this list are making in preparation for Sarbannes Oxley compliance. Specifically, is anyone making a conscious effort to remove daily admin rights from people whose job it is to do domain administration, in favor of a “break the glass when needed” type of philosophy? I’m just starting to look into this, but I’m getting the feeling some companies are going overboard. Any observation from the group is always welcome…

 

Mark Creamer

Reply via email to