Home Forums SQL Server 7,2000 Sarbanes-Oxley Need advice on SOX compliant policy for access to generic admin accounts. RE: Need advice on SOX compliant policy for access to generic admin accounts.

  • "SQL Server sys. admin. account "sa" is required to run some functions and replacing this with a named admin account which should have the same access rights as "sa" just does not work sometimes, etc."

    Auditors, let alone SOX auditors, will not be happy that a non-auditable superuser account is in use at all.

    Can you really justify it's use in the cases you alude to?  If recoding is required, then that's what must be done.

    "I cannot believe that there is not a SOX compliant procedure to allow multiple individuals controlled access to generic admin account passwords."

    IMO it's not necessarily individuals, but control of access to high level accounts.  I.e. Support staff apply for it, Security staff authorise it, this gives dual-control.