Archives of the TeradataForum
Message Posted: Thu, 09 Feb 2006 @ 16:43:18 GMT
Subj: | | Re: PMON Logon source and Batch Account Tracking |
|
From: | | Yonina.Schuchman |
Instead of tracking the offenders, why not prevent them from knowing the batch account password?
We keep our batch logon strings in protected datasets. Only the security administrator and the DBA has access to this dataset.
ETL job developers just concatenate the dataset into the JCL or UNIX script when the job is ready to be turned over. They cannot read the
datasets, therefore they cannot even submit jobs with the dataset referenced.
Also, if your batch is being run on a mainframe host, you can disable the id from connecting via the LAN.
Yonina Schuchman
|