24 Mar 2010 (updated 25 Mar 2010 at 10:44 UTC)
»
things to write, 'trusted network and improper invocation of
class 'SOP D14'...
1. we know that one instance of violation of SOP D14
is for
someone to ssh/scp packets from trusted network to untrusted
network. Yet transfer a log file to ftp.emc.com via
anonymous login is not considered a violation. From firefox
within a trusted network, using drop.io plugin, drop a file
to a private drop, i.e.
http://drop.io/websphere/sl000913.pdf had a success run but
later attempts were blocked.
2. We were informed that within sys admin team and
dev team,
no one shall be allowed to create OS account for another
team member on a workstation that is NOT assigned to that
person. This is for compliance with class 'SOP D14'. I shall
argue the invocation of 'SOP D14' in this scenario is wrong
headed!
Argument 1:
Security concerns must be concentrated in the peripheral of
a trusted network. Within trusted networks, if security
concerns overrules trust relationships among team members
and their system resources, this trusted network is going to
be not only inefficient but self-destructive.
Argument 2:
It is impossible to enforce 'SOP D14' within trusted network
if Quality Assurance is going to be done at all among sys
admins & dev team members. What is the difference between
ssh/scp to another member's workstation vs. open your
browser and try this https://url ??? Is my application
working right?
email draft
T.P.,
Your attitude is disaster in itself. You may flatter
yourself with Oracle DBA, Oracle Forms/Reports designer
titles, it is NOT my pleasure to work with you or to teach
you things you refuse to learn. With all of our effort to
bring you in this team, if I still have to fill out this SAN
form for you, I disqualify you to be on my team and on
disaster recovery team.
I can not hide my contempt for you. We do our job as a team
in ITB. On the contrary to what you attempted to be, speaking
from a
higher moral ground at our unit meeting, you seek favors to
work from home,
to work overtime, more than anyone else on the team and not
as a team but mostly by yourself and
for yourself. ( Don't think I haven't sensed any discomfort
by true professionals at Positron on your work attitude)
So with due respect to all my colleagues who had to put up
with you over the years, I challenge you to earn respect
back from me and from your team.
Sincerely
Yours
team mate
susan