COMPANY
About PowerTech
News & Events
Articles
Careers
Contact Us
 
request a demo >>
submit request >>
RESOURCES & DOWNLOADS
Datasheets
White Papers
Case Studies
Recorded Webinars
Product Downloads & Updates
Register for Product Demo
Open Source Security Policy
Compliance Guide
PowerLock AuthorityBroker provided the separation of duties that SOX auditors are looking for...

Matt Radatti, C&D Technologies,
Computer Operations Manager
Full Case Study
 
 
 
News & Events
Results of this third annual study show that security compliance on the System i not improving.
 
Kent, Wash. - October 24, 2006 The PowerTech Group, Inc. announced today that it has released its third annual review of the state of security on IBM's System i platform (also known as AS/400 or iSeries).  The study is based on the results of 188 different system audits that were conducted by PowerTech over the last 12 months.  The complete results and analysis are published in a whitepaper, which can be downloaded from the PowerTech website at www.powertech.com.   

IBM has architected the System i with industry leading security capabilities. The majority of Fortune 1000 companies have trusted the System i for years to house the most sensiitive and critical applications used for enterprise resource planning (ERP), finance, inventory, and human resources.  These organizations may have been given a false sense of security by their IT auditors and staff, who are unaware of vulnerabilities.
 
"The results of this annual study are consistent with previous years and led us to believe that the majority of AS/400s (System i) are unable to pass an IT audit and comply with government regulations," said Jon Scott,  CEO of PowerTech.  "This study should serve as a wake up call for IT Executives, Administrators and Auditors to the fact that the reputable AS/400 platform is plagued with poorly written applications that do a bad job of protecting critical data."
 
Listed are a few of the examples of the findings that should alert auditors and executives alike:
 
91% of systems don't control or audit changes to data made thru PC access - a violation of COBIT standards, which should be a material weakness.

95% of all systems have more than 10 user with *ALLOBJ (root) authority - a threat to data integrity and an audit deficiency.
 
77% of all systems have more than 20 users with passwords the same as user name – an obvious violation of COBIT and ISO password standards.
 

“Too often projects involving security on the System i are not given the proper priority because the system is assumed to be secure,” says John Earl, PowerTech CTO.  “The data in this study indicates that just like UNIX and Windows platforms, the System i can be very vulnerable.” 

      

The whitepaper includes more than just the results from the assessment of 188 different systems. To assist security professionals who are defining policy across the enterprise, PowerTech also cross references security issues on the iSeries against the Control Objectives for Information Technology (COBIT) framework. The conclusion includes recommendations for remediation of the different control issues uncovered in the survey. 

 
About The PowerTech Group 
PowerTech is your security expert in managing evolving compliance and data privacy threats with automated security solutions for IBM's AS/400 and System i Servers.  Our ServerProven security solutions are straightforward and save your valuable IT resourses, giving you ongoing protection and peace of mind.  
 
Because iSeries and AS/400 servers are used to host particularly sensitive corporate data, it is imperative that you practice proactive compliance security.  As an IBM Advanced Business Partner with over 800 customers worldwide, PowerTech understands corporate vulnerability and the risks associated with data privacy and control.
 
Seattle, WA based PowerTech Group was founded by security experts in 1996.