The trial of the network administrator who refused to give up the passwords to the network ended with a guilty verdict. What controls were missing in this case that led to the incident in the first place? Who do you think should be held responsible for an environment where such an incident can occur?
Tell us what you think.

Comments
The fact that this took place means that safeguards were not in place. Sure, Senior Sys and Net Admins, have a lot of power dealing with domains, networks and the like that they control, however, they too must answer to someone. Most places I done IT jobs, compartmentalize duties. Such as the Helpdesk creates email accounts, or changes passwords. Usually all things are documented as part of the Change Management process. This particular case, Mr. Childs’ manager is responsible, as there should have been a way to override Mr. Childs permissions with higher permissions, in order to avoid exactly this situation.