Quantcast
Channel: SCN: Message List
Viewing all articles
Browse latest Browse all 8808

Re: firefighter log review

$
0
0

Hi Roosevelt

 

Thanks for the details

 

I do wonder what the value and reasoning behind SharePoint. It does seem like a bit of effort and perhap you could look at reviewing the process

 

  1. User wants to use FF Id - they have the set available
  2. Logon to FF Id - force them to enter a Service Call Reference number, etc and have them put all support evidence and justification in there. FF logon has a drop down for Request types that are configured so you could have categories like (incident, request, regular maintenance, change request).
  3. FF Logon notification automatically sent to the controller - they will receive the Logon Summary and justification that the person enter. Train the controllers to read these emails and follow up immediately if they are concerned of account being used
  4. Training to make sure support person exits the FF Id each time they finish an activity (Controller should chase them down.. refer later)
  5. Schedule FF Log report scheduled weekly or whatever frequency to go to each controller
  6. Have you process/sharepoint step and have the Controller upload their review and sign off once they have reviewed. If the FF User follows process the Controller will see Reference to to service calls, etc to check if activity was appropriate. Have a process for managing non-compliance (even friendly reminders and training if they keep forgetting to logout)

 

As far as the tech side of it goes - my next point is that the FF Ids should only have the access that are needed on the account so reduce the size of the log. I.e don't include non-sensitive reporting if you don't want it in the log.

 

Webyndpro/short-cut - yes - but the SICF service has to be activated and authorisations can restrict that.

 

My recommendation is that you visit your security team and get them to give you a high level training of FF and security so you can understand the risk a bit better. Also, trying to find out the reason for reviewers adding items to sharepoint. If you were on version 10.x then you could have used workflow to automate the FF log review and be done with sharepoint and XLS!

 

Regards

Colleen


Viewing all articles
Browse latest Browse all 8808

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>