Originally posted by: YannickBergeron
To prevent your situation, ie difficulty to find trace of what happened and who did that:
root remote login should be disabled
provide root access with sudo
each user using root with sudo should have their own history with timestamp
sudo logging could happen on a remote system with syslog
etc.
at the end, if you provide a user root access, he can do harm and delete his traces. But if he's professional, the trace will remains, you'll be able to understand what happened and analyze why it happended and how it could be prevented, without bashing on the admin who did it.
#AIX-Forum