SCCS Users and Security Model

There are four different user groups, each with a differnt system privileges that require different level of security control: A user can not have multiple user groups privileges. Major security control mechnisms:
SCCS Users and Security Control for Production Document DB
User GroupRestrictionWeb/DB Access Privilage Security CheckSecurity Measure
User I (Internet users)MostSearch, Retrieve, View, Print most recent document in production. Download selected files to local machine. Select from a list of printers. All functions are provided through a Netscape Navigator. NoFirewall on Intranet
User IIILeastAll in User I, plus:
Insert, Delete, Modify, Search, Retrieve, View, Print all document in pending and production area. All functions are provided through a Netscape Navigator.
LeastFirewall,registered DB user with password protection. Allow the user to change password anytime via the Netscape Navigator
DB Admin (root)NoAll in User III, plus:
Assign user name and initial password, all SCCS Production Document DB adminstration, including DB maintainese, backup, recovery, administration of related UNIX file system, etc. Most functions are provided through a Netscape Navigator. Some are via Oracle Tools.
MostFirewall,registered DB user with password protection, Access to all CGI programs are Web-level password enabled. Only allow access from authorized client host. The root user is not allowed to change the password. Only the Oracle DBA can change it.

SCCS Users and Security Control for Pending Document DB
User GroupRestrictionWeb/DB Access Privilage Security CheckSecurity Measure
User IIMostInsert, Modify, Search, Retrieve, View, Print document in pending area. Download selected files to local machine. Select from a list of printers. All functions are provided through a Netscape Navigator. LeastFirewall,registered DB user with password protection. Allow the user to change password anytime via the Netscape Navigator
User IIILeastAll in User II, plus:
Move SCCS documents from pending area to production database. All functions are provided through a Netscape Navigator.
StrongFirewall,registered DB user with password protection,only allow access from authorized client host. Allow the user to change password anytime via the Netscape Navigator
DB Admin (root)NoAll in User III, plus:
Assign user name and initial password, all SCCS Production Document DB adminstration, including DB maintainese, backup, recovery, administration of related UNIX file system, etc. Most functions are provided through a Netscape Navigator. Some are via Oracle Tools.
MostFirewall,registered DB user with password protection, Access to all CGI programs are Web-level password enabled. Only allow access from authorized client host. The root user is not allowed to change the password. Only the Oracle DBA can change it.