Please wait while the page is being loaded Skip this advertisement >
Friday | 5 December, 2008
CIO
Blog: The Politics of Root Access
Esther Schindler 12 August, 2008 15:23:33

Who needs administrative priviledges to a network or website? The network admin obviously does. But others ask for root access, too, whether or not they truly need it. How should an admin-or the IT manager-handle the sensitive political situation when someone asks-no, demands-admin rights for a system when he really shouldn't have them?

This is not a hypothetical situation. Recently, I lurked on a converation in a network admin's discussion group in which one network admin's plight highlighted all the issues in one fell swoop. I'm reposting the meat of the original query here, with his permission, after removing specifics which might give away the poster's identity.

"More often than not," my online buddy wrote, "I find myself in a situation where someone 'higher' than me asks for access to a system, and they feel that their request is beyond question. This person may be the project manager for a project or someone above me in the food chain, but invariably they are always shocked and appalled that I asked why they need the root/admin password to the system. And then that's when the chain of meetings start, to discuss why am I being difficult, not a team player, etc."

"I may not be universally approachable, but I've always politely and respectfully asked my questions to get an understanding of what they were looking for," he wrote. "Experience tells me that often times they think they need root access but really all they need is sudo or a certain right granted, not full blown privileges to the entire system, if they need access at all. But from where I'm sitting, their anger seems to stem from, "This peon spoke back to me; how dare he.'"

For example, at one place I worked at in a time far away, the webmaster asked for the root password to the web servers. I asked him why he needed that kind of access, and the only response I could get was, "Because I need it." Of course I said No. A few days later I'm pulled into a meeting with the head of IT, my manager and the webmaster to discuss why I'm refusing to work with the webmaster.

Users who don't know the operating system certainly shouldn't have the keys to the kingdom, but sometimes that's exactly what they demand. No admin wants to give access to a webmaster who asks, "What's a shell?" The admin doesn't want to be a pain. He just wants to do his job, which is to secure the network and keep it running correctly.

Other admins in the discussion offered what I think are a pretty good list of policies for the network admin to adopt. I'm sure these aren't the only good Rules to Live By we could come up with, but they're a good start.

But before I let you peek at the suggestions, I'd like you to think about this for a moment. Whether you're an admin yourself, a programmer (who believes she needs root access to the production website to solve a development problem), or an IT manager... what's your response to the dilemma? You're the boss, after all; how would you solve this common source of friction? Even if you aren't moved to post a response here (and really, I'd love to see your own solution), scribble down a few thoughts. What would you do?

Got that done? Really? Okay, let's take a look at the suggestions other admins made, so we can compare their answers to yours.

Latest User Comments
There are no comments yet. Be the first to add one!
More about Boss
Featured Whitepaper Sponsors
Market Place
 

Smart SOA World Tour

Discover how SOA can create smarter outcomes for your business.

Attend and learn:

  • How SOA is helping leading companies to become more agile
  • Where you should be applying SOA processes in your company
  • The top SOA implementation mistakes to avoid

Click here for more information.
  • +

    CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II 05 October, 2007 06:00:00

    For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders.
  • +

    CIO Live Podcast #78: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires 28 September, 2007 17:34:25

    For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders.
  • +

    CIO Live Podcast #77: Panasonic Speeds Up Trans-Pacific File Transfers, Part III 21 September, 2007 07:00:00

    Part three in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    CIO Live Podcast #76: Panasonic Speeds Up Trans-Pacific File Transfers, Part II 14 September, 2007 07:00:00

    Part two in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    CIO Live Podcast #75: Panasonic Speeds Up Trans-Pacific File Transfers, Part I 07 September, 2007 07:00:05

    Part one in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    SOA What? Why You Need SOA Governance Framework 04 December, 2008 08:32:00

    Adopting services oriented architecture (SOA) in your enterprise without thinking through IT governance can cause something like the Gold Rush in the 1800s; extreme rates of growth and minimal law and order which produce unexpected outcomes.
  • +

    The Myth of Cloud Computing 04 December, 2008 08:25:00

    Why the rapid spread of virtual technology is becoming a security risk
    Why the rapid spread of virtual technology is becoming a security risk.
  • +

    Who Pushed Vendors Toward Better Security? 04 December, 2008 09:38:00

    Hint: It had something to do with pressure from customers and government agencies, writes Oracle CSO Mary Ann Davidson
    Hint: It had something to do with pressure from customers and government agencies, writes Oracle CSO Mary Ann Davidson.
  • +

    CPO & CISO: A Comprehensive Approach to Information 04 December, 2008 08:42:00

    GE CPO Nuala O'Connor Kelly advocates greater CPO/CISO cooperation to place the right value on information assets.
    GE CPO Nuala O'Connor Kelly advocates greater CPO/CISO cooperation to place the right value on information assets.
  • +

    Virtually every Windows PC at risk, says Secunia 04 December, 2008 08:00:00

    Almost all PCs scanned by patch tool have an unpatched app; 46% have 11-plus.
    More than 98% of Windows computers harbor at least one unpatched application, and nearly half contain 11 or more programs at risk from attack, a Danish security company said Wednesday.
CIO Webcast Innovation #8 - What are the biggest roadblocks to IT's involvement in innovation at your company?
Watch the latest latest edition of CIO Innovation which is now available for download.
Watch the webcast
Sign up to the CIO Innovation update email


CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II
Listen to the latest edition of CIO Live which is now available for download.
Listen to the podcast
Sign up to the CIO Live email
Whitepaper

Controlling storage costs with Oracle database 11g

Organisations must embrace new ways of storing data that don't involve adding more of the same hardware to accommodate data growth and dealing with duplication as well as uncompressed information. Simple steps such as tiering storage, moving data across these tiers and reducing the amount of data to be managed, can dramatically reduce capital and operating expenses. Read on to learn how to implement these steps in your business.