Over a million developers have joined DZone.

Do You Trust Your Admin?

DZone's Guide to

Do You Trust Your Admin?

· Cloud Zone
Free Resource

MongoDB Atlas is a database as a service that makes it easy to deploy, manage, and scale MongoDB. So you can focus on innovation, not operations. Brought to you in partnership with MongoDB.

I recently listened to a demo done by a software vendor that was running a cloud based service. One of the questions that came up was around how the end user verifies that their data is safe. It wasn’t the question of being safe from hackers but rather the cloud vendor’s own admins. This started a huge internal debate on the VMware cloud team on how, when, and why you should audit your administrator’s activities.

There are probably several answers to this question and I would be really interested to get some comments on how people look over their admins (or don’t) in their own environments. My personal answer to this is if you don’t trust someone that has all the root passwords and a key card to your physical datacenter then you have much bigger issues at hand versus making sure they aren’t touching people’s data.

Still internal issues do pop up. I remember an incedent when I worked for the Department of Revenue in the state of Georgia many years ago. Turns out some of the people on the security team were running a “credit cleaning” business. For a certain sum they would log in and clean up your credit record since the state holds a lot of power to do so. Of course after several months of this they were escorted out of the building one day by the FBI. But how did these people get caught? It wasn’t anything too high tech. They simply got greedy, put out ads, and one of the ads turned up on the GBI (the state FBI) bulletin board. Funny how things work.

Like I said, there are many software packages on the market to audit everything that anyone does, but doesn’t someone also maintain those software packages? Isn’t it usually the same people that have admin access to other systems like the security team? How do you stop something at the very top?

Needless to say this is something my team will be thinking about and building into the cloud architectures that we build. Just thought I’d bring it up and start a conversation to see what other people think can be done for this issue.

MongoDB Atlas is the best way to run MongoDB on AWS — highly secure by default, highly available, and fully elastic. Get started free. Brought to you in partnership with MongoDB.


Published at DZone with permission of Mike Dipetrillo, DZone MVB. See the original article here.

Opinions expressed by DZone contributors are their own.


Dev Resources & Solutions Straight to Your Inbox

Thanks for subscribing!

Awesome! Check your inbox to verify your email so you can start receiving the latest in tech news and resources.


{{ parent.title || parent.header.title}}

{{ parent.tldr }}

{{ parent.urlSource.name }}