Difference between revisions of "Security Basics"
From MidrangeWiki
(→Sky View) |
m (→Milt Habek) |
||
Line 45: | Line 45: | ||
=== Milt Habek === | === Milt Habek === | ||
− | Milt is CEO of UPI which markets many security solutions for the 400 | + | Milt is CEO of Unbeaten Path International [[UPI]] http://www.unbeatenpathintl.com/ which markets many security solutions for the 400, and stuff for [[ERP]] such as [[BPCS]]. |
+ | |||
+ | * IT Security Assurance Navigation http://www.unbeatenpathintl.com/ITsecure/source/1.html Has articles on | ||
+ | ** why we need better security | ||
+ | ** gov regulation and compliance needs | ||
+ | * Sarbanes Oxley SOX Info | ||
+ | * Security Compliance Products from UPI http://www.unbeatenpathintl.com/compliancecatalog/source/1.html | ||
+ | ** Bill of Health | ||
+ | *** This software examines the security of your 400 and provides a report listing what needs to be fixed. Then after you have resolved some issues, run it again. Use this to document to auditors that you making progress with your 400 security remediation. | ||
+ | ** Stitch in Time | ||
+ | *** This monitors who messed with critical data when doing what ... you decide which files and fields need monitoring | ||
=== Sky View === | === Sky View === |
Revision as of 08:07, 10 June 2005
See General Computer Security for info and links about Security outside of the 400.
Security 400 Professionals
Wayne Evans
- Wayne O. Evans http://www.woevans.com/ is a former IBM 400 Security Architecture specialist http://woevans.freeyellow.com/WOEBIO.html who now has his own 400 Security Consulting firm
- He designed many of the security features of the 400 and its predecssor machines, also many 400 features in addition to security
- He advises us to get a more secure web browser than Microsoft IE
- He does 400 Security columns and seminars
- He has a book out with a collection of his 400 Security articles
- OS/400 Security Education and Training
- Security/400 FAQ
http://woevans.freeyellow.com/Qst_Ans.pdf
- Biggest threats to overall 400 security
- Best Practices
- What can be done at the Sign On Screen
- How secure are 400 passwords
- Why security level 40
- Security 400 auditing
- Client Access
- Operations Navigator
- Exit Programs
- Authorization Lists
- ODBC
- Encryption 400
- How evaluate security software vendors
- VPN interesting factoid
- The use of VPN (Virtual Private Network) causes all traffic over the VPN to be encrypted.
- Al Mac notes that this may not help if Spyware gets onto the PC of the person using VPN to access the 400
- and lots more
- Other downloads available http://www.woevans.com/My_Homepage_Files/Page3.html such as
- step by step instructions to improve your 400 Security
- sample Security Policy
- Security related software
- History of 400 and predecessor machines
- Other downloads available http://www.woevans.com/My_Homepage_Files/Page3.html such as
- OS/400 Security Review Audit
- OS/400 Security Training
- NetQ PentaSafe Training
- His links to Security 400 user groups, discussion forums, and related info http://www.woevans.com/My_Homepage_Files/Page1.html
- 400 user groups in gneral http://www.woevans.com/usergroups.html
Milt Habek
Milt is CEO of Unbeaten Path International UPI http://www.unbeatenpathintl.com/ which markets many security solutions for the 400, and stuff for ERP such as BPCS.
- IT Security Assurance Navigation http://www.unbeatenpathintl.com/ITsecure/source/1.html Has articles on
- why we need better security
- gov regulation and compliance needs
- Sarbanes Oxley SOX Info
- Security Compliance Products from UPI http://www.unbeatenpathintl.com/compliancecatalog/source/1.html
- Bill of Health
- This software examines the security of your 400 and provides a report listing what needs to be fixed. Then after you have resolved some issues, run it again. Use this to document to auditors that you making progress with your 400 security remediation.
- Stitch in Time
- This monitors who messed with critical data when doing what ... you decide which files and fields need monitoring
- Bill of Health
Sky View
One of the founders of Skyview is Carol Woodbury, who is also one of the mothers of IBM 400 Security architecture, former Chief Security Architect for OS/400 for IBM and one of the leading authorities on OS/400 security.
http://www.skyviewpartners.com/java-skyviewp/index.jsp
Skyview offers 400 Security and General Computer Security info
- education
- assessment
- security tools
- remediation services
- compliance info about gov regulations
- white papers