Home > Ask the Networking Experts > Network administration with Lindi Horton Questions & Answers > How can I persuade my boss from letting users have administrative access to their machines?
Ask The Networking Expert: Questions & Answers
EMAIL THIS

How can I persuade my boss from letting users have administrative access to their machines?

Lindi Horton EXPERT RESPONSE FROM: Lindi Horton

Pose a Question
Other Networking Categories
Meet all Networking Experts
Become an Expert for this site


Network management news, advice and technical information
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


>
QUESTION POSED ON: 27 July 2007

I have a real hard time trying to persuade my boss that users should not have administrative access to their machines. Talk about fuzz factor! Half of the hours are spent in ICQ, Skype, porn sites, matchmaking, tweaking, CD/DVD-copying, etc. Where can I obtain relevant information that I could cite as argument?


>
EXPERT RESPONSE

As is my favorite engineering answer: it depends. My best advice to you is to learn to speak to your manager as a manager would understand your point of view. For example, you give many technical reasons why users in your organization should not have administrative rights on their machines. However, to create a policy of that nature, you would want to quantify this reasoning in a way that your management team would understand.

First, log how many hours you (your team) spend working on correcting and troubleshooting individual PC problems. By logging the number of hours and incidents, you can first identify if there are recurring instances by a particular user. This user or set of users would be the first to implement a policy of restricted access. Second you can use this number as an indicator for how often you and your team are spent troubleshooting an issue. This time takes you away from other key strategic initiatives that the management teams wants you to focus your time on, e.g. new application rollouts, improving the network backbone, or upgrading servers. In my experience, this falls right in line with the classic 80/20 rule. Eighty percent of the problems are coming from 20% of the users. Perhaps the management team would be more amenable to implementing a policy for those 20% users without affecting the entire user population.

Second, one of your better arguments for enforcing some sort of security policy would be to argue productivity of the users. Non-business critical applications require resources, bandwidth, and are inefficient uses of people's work hours and time. The easiest way to quantify this is to provide metrics around bandwidth consumption for non business critical applications (NetFlow/IPFIX/SFLOW, etc.). Most security related events these days with regard to intellectual property stem from abuses of email and other internal systems. You can argue that productivity is lost for these users and design a strategy to limit their access to certain Web sites.

Of course I would be remiss if I did not warn you that implementing this policy could make you very unpopular in the eyes of your end users. Also be aware that enforcing these policing activities also requires your time and energy. For users with these policies in place, they will request special access to read or get some essential item for their work. They will also be forced to ask you to help them install software that will help them do their jobs. It is essential to understand administrative costs of these types of policies prior to implementing them.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Network administration with Lindi Horton
What training do I need for a career in network administration?
On a full-duplex T1 circuit, what's the bandwidth speed in both directions?
What is the role of a network administrator?
How can I resolve this remote worker's VPN connection problem?
LANs vs. WLANs: Which network designs are used for each company size?
How can I be sure no one is hijacking or hacking my WAP?
Will mixing 802.11g and n APs in the same network cause conflicts?
How can I get reliable voice data (VoIP QoS) through ISDN circuits?
What correlation does ping latency have with high server activity?
What are three vital pieces of criteria used to evaluate a network?

Network Monitoring
Return-all-values script: Managing Windows networks using scripts, Part 13
HTTP error code troubleshooting, Part 2: How to use IIS tool WFetch
Network management software vendors offer virtualization management
Hospital gains network visibility by convincing vendors to collaborate
NagVis -- 'Nagios: System and Network Monitoring, Second Edition,' Chapter 18
Monitoring your enterprise network with Solarwinds' ipMonitor
Retrospective network analysis might have found Google's lost billions
What correlation does ping latency have with high server activity?
Measure wireless network performance using testing tool iPerf
Why wireless network cards show activity when no one uses the computer
Network Monitoring Research

Network Documentation
TCO calculations can fall short when budgeting network expenses
Networking data visualization not just for pointy-headed bosses
Virtual machines present dynamic environment issues for network pros
Network configuration management software boosts university networking
What is the document flow of enterprise-level network consulting?
As network configuration management matures, documentation woes linger
BICSI separation requirements between cross-connect points
Is there Cisco router documentation for proactive and reactive checklists?
What licenses allow user access to applications on the server?
To evaluate network management, what criteria is there?

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
10-high-day busy period  (SearchNetworking.com)
ACK  (SearchNetworking.com)
baseboard management controller  (SearchNetworking.com)
call failure rate  (SearchNetworking.com)
jam  (SearchNetworking.com)
Jini  (SearchNetworking.com)
maximum segment size  (SearchNetworking.com)
maximum transmission unit  (SearchNetworking.com)
netstat  (SearchNetworking.com)
network tracking tool  (SearchNetworking.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Expert networking advice and tips for IT professionals
HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersNetworking Product Trials
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2000 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts