Previous Topic: Expanding Native Security

Next Topic: CA Access Control Administrators


Superuser Account Limitations

Users who administer and manage the operating systems are typically members of predefined accounts that are automatically created during system setup, such as the root account on UNIX systems, and the Administrator account on Windows systems. Each of the predefined accounts exists to perform a certain set of system functions.

Users acting as root or Administrator can perform a wide range of tasks, from creating, deleting, and modifying users to locking, reconfiguring, and shutting down servers.

One of the major security risks in these operating systems is that an unauthorized user can gain control of these accounts. If this happens, the user can cause enormous damage to the system.

CA Access Control lets you limit the rights granted to these accounts and to limit the rights of users who are members of the user groups that have these accounts as members. This reduces the vulnerability of your operating system.