sudo is fine, and I like the concept of Ken's suggestion.  Just need to flesh out some details, but conceptually, it sounds like a good approach.

Agreed.  Tweaking sudo can be done through the normal change management channels.  Relaxing network "security" (such as direct root login via ssh) would involve an entire world of pain starting with the security team.  Mind you, they have some rather odd ideas of what constitutes security.  So far, it seems, obscurity is just as good as security, as long as the auditors are happy (clueless imbeciles...all of them) and PCI compliance isn't affected.

DO NOT get me started on PCI compliance...grrrr: "Hey look at me, I'm PCI Compliance! I'm a thick as two short planks and read a security appliance catalogue once....you need two of everything in it!". *slaps forehead*



