Is this normal to build this sort of functionality into a software system? Especially software systems that heavily rely on auditability?
Is this normal to build this sort of functionality into a software system? Especially software systems that heavily rely on auditability?
My company retains all e-mails for at least 5 years, for audit purposes. But if some troublemaker were to e-mail child porn to an employee, we'd need to remove that from the audit records, because the laws against possessing child porn don't have an exception for corporate audit records.
So there's essentially always some account with the power to erase things from the audit records.
"No" is the answer to GP: there is no legitimate reason for a fully unlogged superuser account.
If needing things wiped from the audit logs happens often, you might indeed have an audited interface for wiping things from the audit logs.
But if it's very rare? Maybe I just request the production database password for "Incident #12345" and run some careful SQL.
> And there would be other records generated to document the deletion, like I'm sure a long email or slack thread
For sure - but the account capable of deleting entries from the audit logs exists
And if I am ordered to hand it over to someone who doesn't care to explain their actions on slack? Then there won't be any explanations in slack.
From the previous post, they had auditor roles built in that they purposely chose to go around
You always need it to setup the system initially.
It's like root on Linux: it's an implementation detail that it must be possible.
There is no legitimate justification for this request.
But instead they requested that logging be disabled, thus outing themselves as acting in bad faith.
I’ll agree that Linux security is quite limited and primitive if compared with, say, a mainframe, but it can be made less bad with a reasonable amount of effort.
The short answer would be that mainframes come with RBAC from design, unlike Unix, which has a different security model from conception and then had rbac added on top of it in some cases (such as selinux).
I mean, if we were to apply the equivalent from the article, then no they would not have had a reason nor been time gated.