General discussion
October 31, 2007 at 03:54 AM
syadm

Delegation,security and responsibility best practices

by syadm . Updated 18 years, 9 months ago

Hi,

Consider the following scenario:
Your organization manages a complete IT-infrastructure, Networks, Services, servers & clients, software, security (the whole shebang) for a big customer.

The customer has delegated the responsibility for the IT-infrastructure to your organization and this includes SLA agreements(with penalties) towards the customer.

What would you say if one of your customer representatives demanded to have the topmost administrative access to all resources, free to share with anyone he likes? (The customer rep. is not an IT-pro).

If you say yes, would you still feel comfortable having the responsibility for the environment while a customer rep. is out there and might be sharing his Admin/root access with his colleagues?

If you say no, how would you make the customer rep. understand your point. Would you “renounce” the security responsibility in this case?

Should the responsible alone be root?
Is it possible to share this responsibilities over organizations?
What do you think is the best practice in such cases?

Please elaborate!

BR
/ Tom

This discussion is locked

All Comments