プロジェクト

全般

プロフィール

Vote #73471

未完了

Security against Administrators

Admin Redmine さんがほぼ4年前に追加. ほぼ4年前に更新.

ステータス:
New
優先度:
通常
担当者:
-
カテゴリ:
Security_51
対象バージョン:
-
開始日:
2022/05/09
期日:
進捗率:

0%

予定工数:
category_id:
51
version_id:
0
issue_org_id:
13326
author_id:
40634
assigned_to_id:
0
comments:
4
status_id:
1
tracker_id:
2
plus1:
1
affected_version:
closed_on:
affected_version_id:
ステータス-->[New]

説明

We are wanting to add security against certain system administrators for example:

User Administrator will be able to administer to User accounts such as user creation, etc.

Project Administrator will only be able to manage and administer to projects.

The reasoning is that we have some confidential projects that we would like to have system administrators to not have access to it.


journals

+1
--------------------------------------------------------------------------------
The administrator of the underlying OS will most likely have access to the raw data in the database. How would you deal with that?
--------------------------------------------------------------------------------
One person will always have access to the whole thing or at least to parts of it no matter what you do. Even if I do system wide encryption there would be at least one person having access to it. I do not have any issues with that one person since its me. But in my organization we have about 200+ users in the system, and it would be nice for me to delegate some of the task of user maintenance, project maintenance, etc. to others without having to give full access to everything.

But to answer your question to how we protect against the OS admin would be to use some sort of auditing procedures. Redmine doesn't really have any auditing features, but I would do auditing on the DB level to audit who looks into the database.
--------------------------------------------------------------------------------

--------------------------------------------------------------------------------

Admin Redmine さんがほぼ4年前に更新

  • カテゴリSecurity_51 にセット

他の形式にエクスポート: Atom PDF

いいね!0
いいね!0