System administrators and network security
One generally tends to think of system administrators (sys admins) and network security as one and the same. Well one example certainly highlights the perils of completely trusting your sys admin to act in the corporations best interests. The occurrence of sys admins, at times, acting in a criminal manner are not to be ignored by corporations out there today, as that article clearly illustrated. What is helpful in helping to safeguard the network from the odd sys admin who oversteps their bounds, to the criminal, is having your networks audited by outside network security personnel. Such contractors, or outside security service providers can help in detecting such criminal behaviour. Having the penetration test or vulnerability assessment performed is always good, however, at times a network traffic audit by outsiders is helpful. Not to mention simply having an outsider go through key computers looking for evidence of wrong doing. It is money well spent in my opinion.
Technorati Tags: Penetration test, Pen test, Vulnerability assessment, Network security, Sys admin

amit Says:
December 28th, 2006 at 4:17 am
please provide such type of article
Don Parker Says:
December 28th, 2006 at 6:43 am
Hello Amit,
I would suggest you email the editor and request that such an article be written. You may reach him at michaelv [at] techgenix [dot] com Thanks for your comment.
ahmed Says:
January 7th, 2007 at 5:19 am
well sure u r right don..but the idea of this kind of outside monitoring is not accepted in such situations..so what about to make 2 admins in the organization..so that they monitor each other!!
Don Parker Says:
January 7th, 2007 at 7:47 am
Hello Ahmed,
It all comes down to what level of risk you are willing to accept. Yes you can go with two sys admins and hope that at least one of them would be honest enough to report wrongdoing. That or as I mentioned have an outside contractor come in who signs an NDA and then audits the network. Outside of perhaps some high assurance .gov or .mil networks this is commonly done.