who are these "admin" guys?
in the good old days they were civil servants who held your life in those dusty files preserved for posterity in cavernous rooms and filing cabinets.
in todays world they are computer geeks who control the passwords to sensitive data centres. the issue is who has a right to control these passwords? how are these password keepers to be police(d)?
my personal experience has been to leave the admin password to the main server with the owner of the company and get all high level changes in the network code to be done only in the owners presence or his representative with proper background logging of all the activities to enable checking by a third party before the changes are accepted and allowed into the system.
now how would this work in a public system like say a government office? here in india most government offices are under the maintainance of NIC. staff employed there are the people with access to enormous amounts of sensitive data and a lot of them have in the past left government service and joined private sector companies. this puts the entire public record keeping system at risk as there is no visible public policy on password storage and its management issued by the government of india.
the risks of not having such a policy need not be repeated as a single breach of sensitive government records might compromise the security of financial/ personal data of millions of its citizens. i dont see the president or primeminister of a nation to be involved in this but technically as the owners to the data, they are ultimately responsible for the safekeeping of the data collected for "governmental work". big brother is watching - just we dont know which "admin" where is having a peek at your personal records!!
Monday, March 9, 2009
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment