Login, change your address, subscribe to new or manage current magazines or e-newsletter subscriptions
ComputerWorldNetwork WorldCIO CanadaCIO Canada Governments' ReviewJobUniverse Canada
Advanced Search
Knowledge Centres
Content Types
Featured White Papers
Unlock the potential of data with the right data warehouse solutionUnlock the potential of data with the right data warehouse solution read more
IBM Multiform Master Data Management: The evolution of MDM applicationsIBM Multiform Master Data Management: The evolution of MDM applications read more
Closing the data privacy gap: Protecting sensitive data in non-production environmentsClosing the data privacy gap: Protecting sensitive data in non-production environments read more
Yuk it Up
IT Executive Development Series
Some of Canada's leading academics discuss the best leadership practices for a wide range of IT challenges. It's a "must read" for those senior managers and other professionals who spearhead the IT strategies within their organizations.
Featured IT Quiz
IT Quiz: Test yourself to see if you have the knowledge to fit into the open source world, and compare yourself with the rest of the respondents
Featured White Papers
This white paper details Intel's current and future energy-saving initiatives to reduce costs and support business goals. Learn how Intel IT is extending its efforts to be a role model enterprise IT organization by supporting the Climate Savers Computing Initiative, which aims to drive a 50 percent reduction in computer-related CO2 emissions worldwide. No registration required.

Sign-Up for
Enterprise Infrastructure
eNewsletter Delivered Weekly
Click here
Page 1 of 1

IBM System i computers security risk, says study

Advertisement

IBM's System i computers -- formerly known as the AS/400 and iSeries servers -- have long enjoyed a reputation for rock-solid reliability. But poor security practices by those who manage these systems are making them dangerously vulnerable to compromise, according to a recent study.

The report by The PowerTech Group Inc. a Kent, Wash.-based security firm, is based on the results of 188 system audits at 177 System i sites over the past year. The results show that many owners of System i computers are not putting enough internal controls in place to adequately protect data on the systems, said John Earl, chief technology officer at PowerTech.

For instance, more than 90 percent of the surveyed systems had no controls for preventing or auditing changes to the underlying data via an external PC. In addition, 95 percent of the systems had at least 10 users with complete root-access authority, and 43 percent had as many 30 users with root authority. Also, 77 percent of the systems had more than 20 users with passwords that were the same as their usernames.

The results are not much different from two earlier surveys PowerTech conducted of the System i user base. It shows a continuing lack of attention to security, Earl said.

"The platform has always had a great reputation for security and deservedly so," Earl said. "It has some of the best native security tools bundled into the box. But the community out there for a number of reasons has not stepped up to the plate and done their due diligence [around security]. Too often, projects involving security on the System i are not given the proper priority because the system is assumed to be secure."

The System i is a proprietary midrange IBM server that for several years now has powered critical enterprise resource planning, finance and human resources software at both large and small companies. It was first introduced as the AS/400 in 1988 and was originally based almost entirely on a previous-generation IBM midrange system called the System 38. Since then, the platform has gone through several major changes.

Among the most significant of those changes is the inclusion of support for services such as file transfer protocol (FTP), Open Database Connectivity (ODBC) and Java Database Connectivity (JDBC) that have allowed data on System i computers to be accessible to other computers on enterprise networks.

"In the initial days, the box was very proprietary, and people didn't worry about outsiders getting into the data within these systems," said Robin Tatam, senior System i security engineer at MSI Systems Integrators Inc. in Omaha. "Over the years, customers have screamed for more open access through FTP and ODBC, and IBM has delivered on these."

Advertisement

But that openness, coupled with an absence of proper controls, has also made the System i more vulnerable to compromises, he said.

For example, with previous generation "green-screen" AS/400 systems, it didn't much matter if most users had administrator-level access because they were limited in what they could do, Tatam said.

But that has changed with the support for services such as FTP and ODBC, which allow anyone with a profile on the system to access the database on a System i from a PC, he said. As a result, "it is very, very important that enterprises get a handle on the level of access that people have on these systems," Tatam said.

"Open access rights to the data and convenient tools to access the data from a PC make a troublesome combination," the PowerTech report noted. But few companies have put in place controls for limiting or monitoring this access, it said.

Much of the current attitude towards security on the System I has been shaped by user experiences of the past, said Al Barsa, president of Barsa Consulting Group LLC in Purchase, N.Y. "Keep in mind there are a lot of users who came from the S/38, which allowed you to be real sloppy with security," Barsa said. "It was a very simplistic computer to use" from a security standpoint, and early implementations often didn't even require passwords, he added.

"A lot of those practices carried over to the AS/400" and have persisted to this day, Barsa said. "Historically, this platform has been so robust that people have been able to get away with a lot of bad [security] practices."

Page 1 of 1
Send to a Friend  Rate This Page  Print This PageAdd a new comment

Bookmark this article on:
del.icio.us| Digg it| Furl| Google| Technorati| StumbleIt| Yahoo!

Have something to say about this article? Add a new comment

If you find a comment inappropriate, You can notify the moderator by clicking the Report an innapropriate comment icon.
ADD A COMMENT
Name:*Your email address will not appear online and will be used only in the event that the editor wishes to contact you personally for additional comment.
City:
Email:
Title:*
Comment:*
* required fields


Related Content
Articles

Events

Technology Moment podcasts
IDC Case Study: Identity And Access Management Buying Criteria.
IDC analyses IAM buying criteria and deployment at Coppin State University. Coppin State replaces "first generation" IAM solution to obtain benefits needed for today's agile enterprise: ease of integration, rapid deployment, simplified compliance, flexibility.
White Papers
Closing the data privacy gap: Protecting sensitive data in non-production environments
How can IT organizations protect sensitive data, including employee and customer information, as well as corporate confidential data and intellectual property? Industry analysts recommend "de-identifying" or masking data as a best practice for protecting privacy. This white paper explains the importance of closing the data privacy gap in non-production environments, and provides guidance on effective data masking. Complimentary with registration. Sponsored by IBM.
E-mail a Friend
Unlock the potential of data with the right data warehouse solution
Once you've made the decision to implement a new data warehouse, you want to make sure you choose the one that's right for your organization. This buyer's guide provides checklists for starting points that you can use when evaluating vendors and their products. Complimentary with registration. Sponsored by IBM.
E-mail a Friend
Prepare for a more efficient SAP implementation: Take data issues off the critical path
This white paper outlines how the Preliminary Data Assessment Appliance (PDAA) from IBM can help address the challenges of integrating data from different operational applications across the enterprise to an SAP platform. Complimentary with registration. Sponsored by IBM.
E-mail a Friend
Address IT costs and streamline operations with IBM service request and asset management solutions.
This brochure describes how IBM service request and asset management solutions help IT integrate incident, problem, change and release management. Complimentary with registration. Sponsored by IBM.