Design and implementation errors, system generation and maintenance problems, and deliberate penetrations resulting in modifications to the operating system can produce undesirable effects in the application system. Flaws in the operating system are often difficult to prevent and detect:• User jobs may be permitted to read or write outside assigned storage area.• Inconsistencies may be introduced into data because of simultaneous processing of the same file by two jobs.• An operating system design or implementation error may allow a user to disable controls or to access all system information.• An operating system may not protect a copy of information as thoroughly as it protects the original.• Unauthorized modifications to the operating system may allow a data entry clerk to enter programs and thus subvert the system.• An operating system crash may expose valuable information, such as password lists or authorization tables.• Maintenance personnel may bypass security controls while performing maintenance work. At such times the system is vulnerable to errors or intentional acts of the maintenance personnel, or anyone else who might be on the system and discover the opening (e.g., micro coded sections of the operating system may be tampered with orsensitive information from online files may be disclosed).• An operating system may fail to maintain an unbroken audit trail.• When restarting after a system crash, the operating system may fail to ascertain that all terminal locations previously occupied are still occupied by the same individuals.• A user may be able to get into a monitor or supervisory mode.• The operating system may fail to erase all scratch space assigned to a job after the normal or abnormal termination of the job.• Files may be allowed to be read or written prior to being opened by the operating system.
đang được dịch, vui lòng đợi..