You are here:About>Business & Finance>Business Security> Security Policies> Terminating a Rogue System Administrator
About.comBusiness Security
Newsletters & RSSEmail to a friendSubmit to Digg

Terminating a Rogue System Administrator

From Ryan Groom,
Your Guide to Business Security.
FREE Newsletter. Sign Up Now!

Intermediate Steps to Take When Firing a Rogue System Administrator

This phase is completed immediately following the primary stage. This phase deals with more of a monitoring capacity. At this point you have stopped all immediate threats and now need to know if anyone is trying to get back in. Monitoring web logs and VPN traffic is especially important as these are likely vectors a disgruntled employee could exploit as they no longer have internal access.

Monitoring

  • Note all strange traffic and increased traffic
  • Consider an IDS or other monitoring system to be alerted when such anomalies are occurring
  • Ensure Firewall logs are monitored
  • Pull Server logs and search for unauthorised attempts to escalate privileges or logon attempts
  • Pull Remote Access logs and ensure there are no unauthorised logon attempts for known accounts or attacks on numerous accounts.
  1. Overview
  2. Primary Steps to Take When Firing a Rogue System Administrator
  3. Intermediate Steps to Take When Firing a Rogue System Administrator
  4. Continual Steps to Take When Firing a Rogue System Administrator
  5. Summary

<< Previous | Next >>

 All Topics | Email Article | | |
Advertising Info | News & Events | Work at About | SiteMap | Reprints | HelpOur Story | Be a Guide
User Agreement | Ethics Policy | Patent Info. | Privacy Policy©2008 About, Inc., A part of The New York Times Company. All rights reserved.