DBA Shared ID and Password Management Guide
DBA Shared ID and Password Management Guide
Reviewing and validating SHC report deviations before implementing fixes ensures that any actions taken align with the current security IM and do not inadvertently impact system stability. This process involves careful assessment to avoid introducing new vulnerabilities or disrupting service, thereby maintaining the overall integrity and reliability of the system .
Shared ID management enhances accountability and security by requiring the initiation of check-out and check-in processes when using shared IDs. This process allows for tracking who accessed the IDs and when, thereby maintaining a secure and auditable environment. Furthermore, passwords for shared IDs must be changed every 90 days, and new passwords registered in ITIM to prevent unauthorized access .
Changes to SIA ID privileges should only be done following approval from the SIA. This process ensures that any changes are necessary, justified, and do not compromise system security. Deviations in privilege changes must be communicated to the customer via the security focal for review and further action .
The SA&D process ensures systematic commissioning and decommissioning of databases. The SA&D checklist must be approved by the Designated Process Engineer (DPE) before handing over a new database to the customer. In urgent scenarios, an override of the standard procedure requires DPE approval to ensure compliance and documentation .
To handle deviations discovered during security health checks, it is essential to first review the health check reports and validate all deviations against the current security IM. Deviations should be recorded through CIRATS with a detailed action plan. Fixes should only be applied after careful assessment, ensuring no impact on the system. Comparisons with previous SHC results are necessary before implementing changes .
Best practices for password management include completing an online password management course for all new DBAs, changing shared ID passwords every 90 days (except those with non-expiring passwords), and using a PIM tool to generate strong, compliant passwords for all managed IDs. These practices help maintain system security and prevent unauthorized access .
Database administrators should closely monitor warning and critical alerts, addressing warning alerts as soon as possible so none go unattended. For critical alerts, they need to provide an initial response within 15 minutes. If an incident affects service availability, restoring service should be prioritized to maintain uninterrupted database operations .
Implementers must ensure the timely assessment and approval of changes before the change window. They are responsible for executing changes only after full approval and informing the requestor and change manager if issues arise. If the change window exceeds, seeking concurrence for the next step is vital. Implementers should also close the change the same day, preferably right after requestor confirmation .
Emergency changes can be implemented immediately following approval from the SIA manager. If there are approval delays, the change coordinator may adjust the schedule. This contrasts with major changes, which require the implementer to provide a detailed implementation procedure and impact analysis to the change manager. These documents must be attached to the change request before proceeding .
GDC China is responsible for tracking and reporting outstanding or overdue security activities, such as QEV, CBN, SHC, etc., and sending daily updates to management. Subsequently, the respective SMEs need to take prompt actions to resolve these issues and update the status to ensure proactive security management and compliance .