Re: Keylogger or other monitoring method for server
--
ChasT
"Bogwitch" wrote:
> A3C-ITMgr wrote:
>
> > The user is an Administrator, but not the primary Admin. I am the
> > primary, and my directive has come directly from the owner.
>
> No matter where your directive has come from, you need LEGAL authority
> to monitor your users. There is an expectation of privacy unless it is
> explicitly removed. However, IANAL?
>
> > We are running a single server and Small Business Server 2003 which
> > also contains Exchange.
>
> > Our topology is ethernet via 3 switches and we also have a Netgear
> > FVS318 as our only firewall.
>
> It sounds as though you have no policy docs to allow monitoring of this
> type. Seek professional legal advice.
> Implement a written policy NOW! Explain to the company owners that they
> are legally responsible for ALL their users actions UNTIL an acceptable
> use policy is in place which will need to be agreed to by all the users,
> including the owners.
> Without such a policy, you may find any action you take could be
> inadmissable if any court action is required and worse still, you could
> find yourself in court as a defendant. Please tread carefully.
>
> My experience is in the UK. You do not state way where you are from and
> legislation varies from country to country. Having said that, most
> countries will require legal authority to perform such actions.
>
> Bogwitch
>
Sorry for the omission. We are in the U.S. There is virtually no chance
that we will take legal action. We primarily want to prove to ourselves that
there are no reasons to worry about his activities. Most likely, he is
surfing the web and not doing anything illegal or immoral. Worse case, he
will be restricted from logging on to the server.
ChasT