<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Providing Readonly access to Base engine libraries in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/Providing-Readonly-access-to-Base-engine-libraries/m-p/205817#M2968</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mike and do not understand what is more trivial for restricting access to data using the OS layers.&amp;nbsp;&amp;nbsp; I only copied that sentence from the SAS manual.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is more of that:&lt;/P&gt;&lt;P&gt;&lt;A href="http://support.sas.com/documentation/cdl/en/bisecag/67045/HTML/default/viewer.htm#n1iplho47r00dvn1exmc26bfitab.htm" title="http://support.sas.com/documentation/cdl/en/bisecag/67045/HTML/default/viewer.htm#n1iplho47r00dvn1exmc26bfitab.htm"&gt;SAS(R) 9.4 Intelligence Platform: Security Administration Guide, Second Edition&lt;/A&gt;&amp;nbsp; (cautions)&lt;/P&gt;&lt;DIV class="xis-cautionLeadin"&gt;+ In the metadata authorization layer, not all permissions are enforced for all items. &lt;/DIV&gt;&lt;DIV class="xis-paraSimple"&gt;It is essential to understand which actions are controlled by each permission. &lt;SPAN class="xis-xrefSee"&gt;&lt;SPAN class="xis-xrefText"&gt;See &lt;/SPAN&gt;&lt;A _jive_internal="true" href="https://communities.sas.com/message/p1b2lkywlgefxcn14v68kok29w1b.htm" title=""&gt;Use and Enforcement of Each&amp;nbsp; Permission&lt;/A&gt;&lt;SPAN class="xis-xrefText"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="xis-cautionLeadin"&gt;+ Some clients enable power users to create and run SAS programs that access data directly, bypassing metadata-layer controls.&amp;nbsp; (Eguide Amo etc) &lt;/DIV&gt;&lt;DIV class="xis-paraSimple"&gt;It is essential&amp;nbsp; to manage physical layer access in addition to metadata-layer controls. &lt;SPAN class="xis-xrefSee"&gt;&lt;SPAN class="xis-xrefText"&gt;See &lt;/SPAN&gt;&lt;A _jive_internal="true" href="https://communities.sas.com/message/n1qolrshjf8h6un13bp6rfjg3ofh.htm" title=""&gt;Access to SAS Data&lt;/A&gt;&lt;SPAN class="xis-xrefText"&gt;.&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="xis-paraSimple"&gt;&lt;SPAN class="xis-xrefSee"&gt;&lt;SPAN class="xis-xrefText"&gt;If you do not the security approach at the OS layer you can eliminate Eguide and AMO usage (EMiner included) from start.&amp;nbsp; &lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="xis-paraSimple"&gt;This chapter once had mentioned some vague to get SAS aligned with common ICT governance policies (standard of good practice).&amp;nbsp;&amp;nbsp; &lt;/DIV&gt;&lt;DIV class="xis-paraSimple"&gt;&lt;A href="http://support.sas.com/documentation/cdl/en/bisecag/67045/HTML/default/viewer.htm#n1cy3v8480k4q6n1ew2mrn0ns2ld.htm" title="http://support.sas.com/documentation/cdl/en/bisecag/67045/HTML/default/viewer.htm#n1cy3v8480k4q6n1ew2mrn0ns2ld.htm"&gt;SAS(R) 9.4 Intelligence Platform: Security Administration Guide, Second Edition&lt;/A&gt; as coming from &lt;A href="http://support.sas.com/documentation/cdl/en/biig/63852/HTML/default/viewer.htm#n1dwbkgpty31pln1ak3sr86qyglj.htm" title="http://support.sas.com/documentation/cdl/en/biig/63852/HTML/default/viewer.htm#n1dwbkgpty31pln1ak3sr86qyglj.htm"&gt;SAS(R) 9.4 Intelligence Platform: Installation and Configuration Guide&lt;/A&gt; (Ongoing System Administration Tasks - checklist for a more secure deployment)&lt;/DIV&gt;&lt;DIV class="xis-paraSimple"&gt;&lt;BR /&gt;Can you explain why SAS doesn't want to cooperate with existing ICT department policies and not according those of regulators but instead of that is obviously fighting those, bypassing them selling it as a solutions with no IT staff needed?&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 03 Apr 2015 13:24:27 GMT</pubDate>
    <dc:creator>jakarman</dc:creator>
    <dc:date>2015-04-03T13:24:27Z</dc:date>
    <item>
      <title>Providing Readonly access to Base engine libraries</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Providing-Readonly-access-to-Base-engine-libraries/m-p/205813#M2964</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Team&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am new to SAS administration. I have to create a base engine SAS library in SAS Management console with readonly access to SAS datasets located at a particular path.&lt;/P&gt;&lt;P&gt;How do make those SAS datasets readonly ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly advice.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Rajesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Mar 2015 16:14:12 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Providing-Readonly-access-to-Base-engine-libraries/m-p/205813#M2964</guid>
      <dc:creator>RAmarapuram</dc:creator>
      <dc:date>2015-03-19T16:14:12Z</dc:date>
    </item>
    <item>
      <title>Re: Providing Readonly access to Base engine libraries</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Providing-Readonly-access-to-Base-engine-libraries/m-p/205814#M2965</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are several options. Which to chose depends on your requirement.&lt;/P&gt;&lt;P&gt;If you just want to protect from accidental updates, just have the libraries not preassigned, or preassigned using Metadata library engine. This is by default a read only access.&lt;/P&gt;&lt;P&gt;But, if your fear that your users will try to bypass metadata engine by assigning the libname directly to the file system path, you might want to look at using Meta Bound libraries. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Mar 2015 16:41:08 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Providing-Readonly-access-to-Base-engine-libraries/m-p/205814#M2965</guid>
      <dc:creator>LinusH</dc:creator>
      <dc:date>2015-03-19T16:41:08Z</dc:date>
    </item>
    <item>
      <title>Re: Providing Readonly access to Base engine libraries</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Providing-Readonly-access-to-Base-engine-libraries/m-p/205815#M2966</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Define the location were the SAS library is stored as read-access at the OS level. &lt;BR /&gt;The datasets wil be set read-only internal by SAS automatically. As you are safe at he OS level there are no issues to solve with SAS settings.&amp;nbsp; &lt;BR /&gt;Even the bound libraries will not protect those from copy at the OS level. &lt;A href="http://support.sas.com/documentation/cdl/en/seclibag/66930/HTML/default/viewer.htm#p0f9aq5vtdli0qn1tyv9ja703xeg.htm" title="http://support.sas.com/documentation/cdl/en/seclibag/66930/HTML/default/viewer.htm#p0f9aq5vtdli0qn1tyv9ja703xeg.htm"&gt;SAS(R) 9.4 Guide to Metadata-Bound Libraries, Second Edition&lt;/A&gt;&lt;/P&gt;&lt;DIV class="xis-paragraph"&gt; &lt;/DIV&gt;&lt;DIV class="xis-paragraph"&gt;If all of the following circumstances exist, it makes sense to consider using metadata-bound&amp;nbsp; libraries: &lt;BR /&gt;- You have SAS data sets that require a high level of security, with access distinctions at the user or group level. &lt;/DIV&gt;&lt;DIV class="xis-paragraph"&gt;&lt;DIV class="xis-listUnordered"&gt;&lt;DIV class="xis-paraSimpleFirst"&gt;- You are running (or planning to run) a SAS Metadata Server in which your users are registered. &lt;DIV class="xis-paraSimpleFirst"&gt;- &lt;STRONG&gt;You have not already met your security requirements through a combination of physical layer (operating system) separation and customized configuration of your SAS servers.&lt;/STRONG&gt; &lt;DIV class="xis-paraSimpleFirst"&gt; &lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Mar 2015 22:25:44 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Providing-Readonly-access-to-Base-engine-libraries/m-p/205815#M2966</guid>
      <dc:creator>jakarman</dc:creator>
      <dc:date>2015-03-19T22:25:44Z</dc:date>
    </item>
    <item>
      <title>Re: Providing Readonly access to Base engine libraries</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Providing-Readonly-access-to-Base-engine-libraries/m-p/205816#M2967</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jaap's response, especially the item in bold, is a very good response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll add one more trivially easy way to specify a library as read-only.&amp;nbsp; There's a Library access field in SAS Management Console that you can use to specify a library as READONLY (that's the menu choice).&amp;nbsp; See &lt;A href="http://support.sas.com/documentation/cdl/en/bidsag/67493/HTML/default/viewer.htm#p0482liwu9td5tn1q32h16395a5u.htm" title="http://support.sas.com/documentation/cdl/en/bidsag/67493/HTML/default/viewer.htm#p0482liwu9td5tn1q32h16395a5u.htm"&gt;SAS(R) 9.4 Intelligence Platform: Data Administration Guide, Third Edition&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A word of caution. As easy as that setting is to configure, if that metadata setting is not also paired by restricting Write access in the operating system, a user can easily circumvent that setting by writing a program with a user-supplied LIBNAME statement to the data.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Apr 2015 12:44:42 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Providing-Readonly-access-to-Base-engine-libraries/m-p/205816#M2967</guid>
      <dc:creator>MikeMcKiernan</dc:creator>
      <dc:date>2015-04-03T12:44:42Z</dc:date>
    </item>
    <item>
      <title>Re: Providing Readonly access to Base engine libraries</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Providing-Readonly-access-to-Base-engine-libraries/m-p/205817#M2968</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mike and do not understand what is more trivial for restricting access to data using the OS layers.&amp;nbsp;&amp;nbsp; I only copied that sentence from the SAS manual.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is more of that:&lt;/P&gt;&lt;P&gt;&lt;A href="http://support.sas.com/documentation/cdl/en/bisecag/67045/HTML/default/viewer.htm#n1iplho47r00dvn1exmc26bfitab.htm" title="http://support.sas.com/documentation/cdl/en/bisecag/67045/HTML/default/viewer.htm#n1iplho47r00dvn1exmc26bfitab.htm"&gt;SAS(R) 9.4 Intelligence Platform: Security Administration Guide, Second Edition&lt;/A&gt;&amp;nbsp; (cautions)&lt;/P&gt;&lt;DIV class="xis-cautionLeadin"&gt;+ In the metadata authorization layer, not all permissions are enforced for all items. &lt;/DIV&gt;&lt;DIV class="xis-paraSimple"&gt;It is essential to understand which actions are controlled by each permission. &lt;SPAN class="xis-xrefSee"&gt;&lt;SPAN class="xis-xrefText"&gt;See &lt;/SPAN&gt;&lt;A _jive_internal="true" href="https://communities.sas.com/message/p1b2lkywlgefxcn14v68kok29w1b.htm" title=""&gt;Use and Enforcement of Each&amp;nbsp; Permission&lt;/A&gt;&lt;SPAN class="xis-xrefText"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="xis-cautionLeadin"&gt;+ Some clients enable power users to create and run SAS programs that access data directly, bypassing metadata-layer controls.&amp;nbsp; (Eguide Amo etc) &lt;/DIV&gt;&lt;DIV class="xis-paraSimple"&gt;It is essential&amp;nbsp; to manage physical layer access in addition to metadata-layer controls. &lt;SPAN class="xis-xrefSee"&gt;&lt;SPAN class="xis-xrefText"&gt;See &lt;/SPAN&gt;&lt;A _jive_internal="true" href="https://communities.sas.com/message/n1qolrshjf8h6un13bp6rfjg3ofh.htm" title=""&gt;Access to SAS Data&lt;/A&gt;&lt;SPAN class="xis-xrefText"&gt;.&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="xis-paraSimple"&gt;&lt;SPAN class="xis-xrefSee"&gt;&lt;SPAN class="xis-xrefText"&gt;If you do not the security approach at the OS layer you can eliminate Eguide and AMO usage (EMiner included) from start.&amp;nbsp; &lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="xis-paraSimple"&gt;This chapter once had mentioned some vague to get SAS aligned with common ICT governance policies (standard of good practice).&amp;nbsp;&amp;nbsp; &lt;/DIV&gt;&lt;DIV class="xis-paraSimple"&gt;&lt;A href="http://support.sas.com/documentation/cdl/en/bisecag/67045/HTML/default/viewer.htm#n1cy3v8480k4q6n1ew2mrn0ns2ld.htm" title="http://support.sas.com/documentation/cdl/en/bisecag/67045/HTML/default/viewer.htm#n1cy3v8480k4q6n1ew2mrn0ns2ld.htm"&gt;SAS(R) 9.4 Intelligence Platform: Security Administration Guide, Second Edition&lt;/A&gt; as coming from &lt;A href="http://support.sas.com/documentation/cdl/en/biig/63852/HTML/default/viewer.htm#n1dwbkgpty31pln1ak3sr86qyglj.htm" title="http://support.sas.com/documentation/cdl/en/biig/63852/HTML/default/viewer.htm#n1dwbkgpty31pln1ak3sr86qyglj.htm"&gt;SAS(R) 9.4 Intelligence Platform: Installation and Configuration Guide&lt;/A&gt; (Ongoing System Administration Tasks - checklist for a more secure deployment)&lt;/DIV&gt;&lt;DIV class="xis-paraSimple"&gt;&lt;BR /&gt;Can you explain why SAS doesn't want to cooperate with existing ICT department policies and not according those of regulators but instead of that is obviously fighting those, bypassing them selling it as a solutions with no IT staff needed?&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Apr 2015 13:24:27 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Providing-Readonly-access-to-Base-engine-libraries/m-p/205817#M2968</guid>
      <dc:creator>jakarman</dc:creator>
      <dc:date>2015-04-03T13:24:27Z</dc:date>
    </item>
  </channel>
</rss>

