Customer Reviews


2 Reviews
5 star:    (0)
4 star:    (0)
3 star:    (0)
2 star:    (0)
1 star:
 (2)
 
 
 
 
 
Average Customer Review
Share your thoughts with other customers
Create your own review
 
 
Only search this product's reviews
Most Helpful First | Newest First

3 of 4 people found the following review helpful:
1.0 out of 5 stars Not a good source for recent AS/400 info, April 15, 2003
This review is from: Auditing and Security: AS/400, NT, UNIX, Networks, and Disaster Recovery Plans (Hardcover)
Because the book was published in 2001, and it used the AS/400 name in it's title, I expected it to be a good source on recent developments in security on the AS/400 (AKA the IBM iSeries). I am dissapointed. While the information that is included in the book seems generally accurate (I have a few quibbles in areas like QSECURITY, Adopted Authority, CHGSYSLIBL, and CRTAUT to name a few), the big problem is that there are huge chunks of current technologies that are not even addressed in this audit standard.

Some examples include, the entire IFS (Integrated File System), Operations Navigator, NetServer and other network servers like SMTP, HTTP, FTP, etc. No reference to exit programs beyond the ancient PCSACC and DDMACC network attirbutes, spotty acknowledgement of System Values added after V3R1 (1995?) and a general lack of understanding of what the potential security exposures might be in areas that were audited. It's one thing to say that you should "discuss with management" the existance on a workstation entry in subsystem QDSNX, but what is an auditor to discuss if the author hasn't explained the potential security exposure?

It may be a rally good book with respect ot the other OS's that it purports to cover, but from an OS/400 perspective it is not current enough to be very effective on modern versions.

Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


1.0 out of 5 stars Not intended for auditors, September 18, 2009
By 
Dave (New York, NY) - See all my reviews
This review is from: Auditing and Security: AS/400, NT, UNIX, Networks, and Disaster Recovery Plans (Hardcover)
As an experienced Technology Auditor, I picked up this book to brush up on some of the considerations involved in auditing UNIX systems. After reading through most of the section on UNIX, I couldnt help but think that this book was written without considering the intended audience. Generally speaking, an IT Auditor has to be a jack-of-all-trades when it comes to systems, because it is extremely difficult to find a company that uses ONLY Unix, or ONLY Windows, or ONLY Linux. As a result, the IT Auditor has to know enough about each system to navigate through, but is not necessarily an expert in any of them.

This book seems to be written for a security administrator, assuming that the reader knows the details of every command the system has to offer and offering little or no explanation as to what the command does. Convincing a system administrator to run a command that you, as the auditor, do not understand is potentially disasterous.

Beyond that, typos and spelling errors within the commands (ex: using "is -1" instead of "ls -l" or "chcl" instead of "chacl"), are simply inexcusable for what they are charging for this book.
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


Most Helpful First | Newest First

This product

Auditing and Security: AS/400, NT, UNIX, Networks, and Disaster Recovery Plans
Auditing and Security: AS/400, NT, UNIX, Networks, and Disaster Recovery Plans by Yusufali F. Musaji (Hardcover - February 21, 2001)
$168.50
In Stock
Add to cart Add to wishlist