18
Thu, Apr
5 New Articles

Security Patrol: The Things for Which I'm Thankful

IBM i (OS/400, i5/OS)
Typography
  • Smaller Small Medium Big Bigger
  • Default Helvetica Segoe Georgia Times

When I say I am thankful for the features of OS/400 security, I'm serious. After all, those features have given me a career both at IBM and now in my own business. So I thought that you might appreciate a discussion of those features.

A Strong Team in Rochester

Let's give credit where credit is due: to the architects, designers, and coders of not just OS/400 security but all of OS/400, System Licensed Internal Code (SLIC), and the AS/400 and iSeries hardware. Throughout the years, they have understood that integrated security is one of the key features of this system and, almost without exception, have added new features each release. In addition, IBM regularly adds integrity features that you'll never read about in the New Release Announcement documentation to ensure the integrity of data residing on OS/400 as well as the integrity of OS/400 itself. Unlike Microsoft, which started a security initiative to educate their programmers only within the last couple of years, developers at IBM Rochester have it drilled into their heads from the time they author their first design document that designs and the subsequent implementation must follow certain standards.

I am so thankful that I don't get those pop-up balloons stating "New updates are ready for download" every time I log on to my iSeries like I do when I log on to my Windows-based PC. Have you ever compared the number of integrity PTFs IBM has put out for OS/400 with the number of security updates for Windows XP? Try counting them sometime. But you'll have to use your calculator for the plethora of Microsoft updates whereas you'll need only your fingers--and perhaps your toes in a "bad" year--for those IBM PTFs.

I am thankful for the strong team at IBM Rochester.

A Strong Core

OS/400 has some security features that make my current position much more enjoyable and much easier. These features are often overlooked, but are invaluable to a security administrator or, in my case, a security consultant.

Virus Resistance

OS/400--while not virusproof--is "virus resistant." I won't go into the gory details; you can find those in a white paper Patrick Botz and I co-authored. But I am thankful that it will most likely not be an OS/400 virus that makes the next headlines.

Security Tools

Perhaps the position of security administrator has a lot of turnover. Otherwise, I can't explain why administrators are still unaware of the security tools that were added way back in V3R2 and V3R7. Among my favorites are the tools that allow administrators to manage users by finding users with default passwords, automatically disabling profiles that are deemed to be "inactive," and printing the attributes of all users in a readable, printable report. I also appreciate the Print Private Authority (PRTPVTAUT) and Print Public Authority (PRTPUBAUT) commands.

OS/400 Commands

Among the commands for which I'm thankful are Display User Profile (DSPUSRPRF) and its numerous options as well as the commands that have been updated to include objects in the Integrated File System (IFS), such as Work with Objects Owned (WRKOBJOWN). Many administrators don't realize that DSPUSRPRF isn't just for displaying user profile attributes. My favorite options of this command allow you to see a list of objects the profile owns, a list of objects authorized (in other words, the objects to which the profile has a private authority), and the members if the profile is a group profile. DSPUSRPRF also allows you to send the information about all user profiles to an outfile. From that outfile, you can do all sorts of queries to find out interesting information about the profiles on your system. You can even download that file into an Excel spreadsheet, which I do to provide information to my clients. I am thankful for OS/400 commands that provide interesting information and allow me to be flexible on how I "harvest" the information.

Auditing

I am thankful for the integrated auditing features that OS/400 provides. It helps my clients perform investigation of security events, determining, without a doubt, what action took place and who performed the action. I find OS/400's auditing features incredibly useful when I'm debugging security issues--especially when I'm helping clients tighten their security implementations. For example, when an end-user calls in to report a problem, I can quickly determine whether the issue is security-related by scanning the audit journal for authority failure entries. I have found that, when a security project is underway, all problems encountered are security-related--at least in the minds of any end-users or programmers who may be involved. Being able to quickly prove whether that's actually the case is quite helpful. Finally, OS/400 auditing provides forensic evidence when a break-in or other security breach occurs. I am thankful for this integrated security feature.

Helpful Manuals

A wealth of information is available from the IBM iSeries Information Center to assist an administrator. My favorite manual that's available from this site is the iSeries Security Reference manual. Chapter 6 has a great table that lists the attributes of an output queue and all the actions you can take against a spooled file and shows what authorities and settings allow what type of action. Chapter 9 provides details about the types of audit journal entries that are produced with each setting of the QAUDLVL (audit level) system value. Appendix B lists all the IBM-supplied profiles and their default settings. This is very helpful when someone has altered the profiles' default settings--typically to add additional special authorities. Appendix D lists all the CL commands shipped with OS/400 and the authorities required to run each one. Appendix F lists the formats for all of the auditing outfiles. I refer to this appendix alone at least once a week. In fact, I use this manual so much that I have downloaded the .pdf to my desktop for quick reference.

Another very useful manual is Tips and Tools for Securing your iSeries (also available from the Info Center), which lists the new technologies added for a particular release and tells me what I need to be concerned about from a security perspective.

I am thankful for thorough information.

Security Organizations

I am thankful for the numerous organizations that provide general security information. NIST and ISO are organizations that provide standards to follow. Computer Security Institute provides interesting security survey results. Security Wire Digest pushes me security-relevant information twice weekly. I am thankful for these organizations that provide me with vital information so I can provide timely information to our clients.

Computer Emergency Response Team (CERT)

CERT provides a safe place to report security vulnerabilities in operating systems as well as protocols and IP applications. CERT endeavors to report vulnerabilities only after they are fixed. Imagine if every vulnerability was reported in the media and there was no organization to control the collection of issues and the disbursement of information regarding the fix. Chaos would reign. While OS/400 does not participate directly in CERT, it does post responses to CERT advisories. Check out the IBM eServer Security Planner for postings as to whether OS/400 is affected by a particular CERT advisory.

Giving Thanks for Things That Matter

Because of the robust security features of OS/400, the various contributions of the Rochester team, and the information I receive from other organizations, I enjoy a successful career as co-owner of SkyView Partners. But there is more to life than a career. And it is this time of year that drives this point home.

I encourage you to ask yourself, "What am I thankful for?" While it's OK to be thankful for your career or job, I encourage you to look outside your career to what really matters and to what is really important in your life.

As I look outside of my career, I am thankful for my parents who were an example of unconditional love--both toward me and toward each other. I am thankful for my brother and sister, who raised me after our parents died and who still think of me as their "little sister." I am thankful for faithful friends, who have helped me through difficult times. I am thankful for my neighbors, whose kids make me laugh. I am thankful for my business partner, who helps me keep my priorities straight. I am thankful for my church, which preaches truth and gives me a firm foundation upon which to build my life. I am thankful for the innocence of a child who helps me appreciate the simple things in life--a hug, a smile, a "thank you, Aunt Carol."

There are many things beyond your career for which to be thankful. I encourage you to not neglect those things and to make sure that you appreciate what's been given to you.

http://www.mcpressonline.com/articles/images/2002/Nov2003Giving%20thanksV400.jpg

Carol enjoys some time with great-nieces Ava and Abby.

Carol Woodbury is co-founder of SkyView Partners, a firm specializing in security consulting and services and the recently released software, SkyView Risk Assessor for OS/400. Carol has over 13 years in the security industry, 10 of those working for IBM's Enterprise Server Group as the AS/400 Security Architect and Chief Engineering Manager of Security Technology. Look for Carol's second book, Experts' Guide to OS/400 Security, to be released later this fall. Carol can be reached at This email address is being protected from spambots. You need JavaScript enabled to view it..


Carol Woodbury

 

Carol Woodbury is President and CTO of DXR Security and has over 30 years’ experience with IBM i Security. She started her career as Security Team Leader and Chief Engineering Manager for iSeries Security at IBM in Rochester, MN. Since leaving IBM, she has co-founded two companies – SkyView Partners and DXR Security. Her current company - DXR Security - specializes in penetration testing for IBM i. Her practical experience together with her intimate knowledge of the system combine for a unique viewpoint and experience level that cannot be matched.

Carol is known world-wide as an author and award-winning speaker on security technology, specializing in IBM i Security topics. She has written seven books on IBM i Security. Carol has been named an IBM Champion since 2018 and holds her CISSP and CRISC security certifications.

 


MC Press books written by Carol Woodbury available now on the MC Press Bookstore.

IBM i Security Administration and Compliance: Third Edition IBM i Security Administration and Compliance: Third Edition
Don't miss the newest edition by the industry’s #1 IBM i security expert.
List Price $71.95

Now On Sale

IBM i Security Administration and Compliance: Second Edition IBM i Security Administration and Compliance: Second Edition
Get the must-have guide by the industry’s #1 security authority.
List Price $71.95

Now On Sale

IBM i Security Administration and Compliance IBM i Security Administration and Compliance
For beginners to veterans, this is the definitive security resource.
List Price $69.95

Now On Sale

BLOG COMMENTS POWERED BY DISQUS

LATEST COMMENTS

Support MC Press Online

$0.00 Raised:
$

Book Reviews

Resource Center

  • SB Profound WC 5536 Have you been wondering about Node.js? Our free Node.js Webinar Series takes you from total beginner to creating a fully-functional IBM i Node.js business application. You can find Part 1 here. In Part 2 of our free Node.js Webinar Series, Brian May teaches you the different tooling options available for writing code, debugging, and using Git for version control. Brian will briefly discuss the different tools available, and demonstrate his preferred setup for Node development on IBM i or any platform. Attend this webinar to learn:

  • SB Profound WP 5539More than ever, there is a demand for IT to deliver innovation. Your IBM i has been an essential part of your business operations for years. However, your organization may struggle to maintain the current system and implement new projects. The thousands of customers we've worked with and surveyed state that expectations regarding the digital footprint and vision of the company are not aligned with the current IT environment.

  • SB HelpSystems ROBOT Generic IBM announced the E1080 servers using the latest Power10 processor in September 2021. The most powerful processor from IBM to date, Power10 is designed to handle the demands of doing business in today’s high-tech atmosphere, including running cloud applications, supporting big data, and managing AI workloads. But what does Power10 mean for your data center? In this recorded webinar, IBMers Dan Sundt and Dylan Boday join IBM Power Champion Tom Huntington for a discussion on why Power10 technology is the right strategic investment if you run IBM i, AIX, or Linux. In this action-packed hour, Tom will share trends from the IBM i and AIX user communities while Dan and Dylan dive into the tech specs for key hardware, including:

  • Magic MarkTRY the one package that solves all your document design and printing challenges on all your platforms. Produce bar code labels, electronic forms, ad hoc reports, and RFID tags – without programming! MarkMagic is the only document design and print solution that combines report writing, WYSIWYG label and forms design, and conditional printing in one integrated product. Make sure your data survives when catastrophe hits. Request your trial now!  Request Now.

  • SB HelpSystems ROBOT GenericForms of ransomware has been around for over 30 years, and with more and more organizations suffering attacks each year, it continues to endure. What has made ransomware such a durable threat and what is the best way to combat it? In order to prevent ransomware, organizations must first understand how it works.

  • SB HelpSystems ROBOT GenericIT security is a top priority for businesses around the world, but most IBM i pros don’t know where to begin—and most cybersecurity experts don’t know IBM i. In this session, Robin Tatam explores the business impact of lax IBM i security, the top vulnerabilities putting IBM i at risk, and the steps you can take to protect your organization. If you’re looking to avoid unexpected downtime or corrupted data, you don’t want to miss this session.

  • SB HelpSystems ROBOT GenericCan you trust all of your users all of the time? A typical end user receives 16 malicious emails each month, but only 17 percent of these phishing campaigns are reported to IT. Once an attack is underway, most organizations won’t discover the breach until six months later. A staggering amount of damage can occur in that time. Despite these risks, 93 percent of organizations are leaving their IBM i systems vulnerable to cybercrime. In this on-demand webinar, IBM i security experts Robin Tatam and Sandi Moore will reveal:

  • FORTRA Disaster protection is vital to every business. Yet, it often consists of patched together procedures that are prone to error. From automatic backups to data encryption to media management, Robot automates the routine (yet often complex) tasks of iSeries backup and recovery, saving you time and money and making the process safer and more reliable. Automate your backups with the Robot Backup and Recovery Solution. Key features include:

  • FORTRAManaging messages on your IBM i can be more than a full-time job if you have to do it manually. Messages need a response and resources must be monitored—often over multiple systems and across platforms. How can you be sure you won’t miss important system events? Automate your message center with the Robot Message Management Solution. Key features include:

  • FORTRAThe thought of printing, distributing, and storing iSeries reports manually may reduce you to tears. Paper and labor costs associated with report generation can spiral out of control. Mountains of paper threaten to swamp your files. Robot automates report bursting, distribution, bundling, and archiving, and offers secure, selective online report viewing. Manage your reports with the Robot Report Management Solution. Key features include:

  • FORTRAFor over 30 years, Robot has been a leader in systems management for IBM i. With batch job creation and scheduling at its core, the Robot Job Scheduling Solution reduces the opportunity for human error and helps you maintain service levels, automating even the biggest, most complex runbooks. Manage your job schedule with the Robot Job Scheduling Solution. Key features include:

  • LANSA Business users want new applications now. Market and regulatory pressures require faster application updates and delivery into production. Your IBM i developers may be approaching retirement, and you see no sure way to fill their positions with experienced developers. In addition, you may be caught between maintaining your existing applications and the uncertainty of moving to something new.

  • LANSAWhen it comes to creating your business applications, there are hundreds of coding platforms and programming languages to choose from. These options range from very complex traditional programming languages to Low-Code platforms where sometimes no traditional coding experience is needed. Download our whitepaper, The Power of Writing Code in a Low-Code Solution, and:

  • LANSASupply Chain is becoming increasingly complex and unpredictable. From raw materials for manufacturing to food supply chains, the journey from source to production to delivery to consumers is marred with inefficiencies, manual processes, shortages, recalls, counterfeits, and scandals. In this webinar, we discuss how:

  • The MC Resource Centers bring you the widest selection of white papers, trial software, and on-demand webcasts for you to choose from. >> Review the list of White Papers, Trial Software or On-Demand Webcast at the MC Press Resource Center. >> Add the items to yru Cart and complet he checkout process and submit

  • Profound Logic Have you been wondering about Node.js? Our free Node.js Webinar Series takes you from total beginner to creating a fully-functional IBM i Node.js business application.

  • SB Profound WC 5536Join us for this hour-long webcast that will explore:

  • Fortra IT managers hoping to find new IBM i talent are discovering that the pool of experienced RPG programmers and operators or administrators with intimate knowledge of the operating system and the applications that run on it is small. This begs the question: How will you manage the platform that supports such a big part of your business? This guide offers strategies and software suggestions to help you plan IT staffing and resources and smooth the transition after your AS/400 talent retires. Read on to learn: