Adding, Changing, and Deleting User Rules

As you study the historical data, add, change, and delete user rules to respond to the access requirements of your organization. Continue to monitor reports and become more familiar with the authorized activity.

At this point it is time to add rules to allow authorized user(s) access at the SERVER level (setting the Audit value to Yes or No based on your auditing requirements). This is done in preparation for public lockdown, where the default (*PUBLIC) rules are set to reject (*REJECT), and all users who are not specifically granted access to them will be locked out. Earlier, under Adding the Initial Rule Set, we already blocked access to the FTPREXEC server for all users. Now, we can create a rule that grants access to that server for specific users only, while all other requests will continue to be rejected.

NOTE: The following steps focus on FTPSERVER, which is a common server to lock down.

Granting authorized access at the SERVER level

NOTE: When creating rules to grant authorized users access to a server, you may decide to add rules using their individual profile, or a group profile they are a member of. Choosing to audit or not audit will depend on whether the accesses or the user activity is required to visible. (Remember that activity is not retained for any user whose Audit flag setting is No.)

Changing and Deleting Profile Rules

As employees depart the company, or move to other roles, it is helpful to develop internal procedures to notify the Exit Point Manager product administrator a user has left, or has changed roles. If individual profile rules are used, their profile should be changed from *OS400 to *REJECT. At some point the profile should be deleted from the product. (If group profiles are used, you would not need to make rule changes in the product, assuming the profile is removed from the system or group.)

Deleting a Rule

  • See Insite Web Browser Help for information on deleting rules using Insite.
  • To delete a rule on the green screen, use 4 (Delete) on the Work with Security by User panel or Work with Security by Location panel.