/ as sysdba only works if you are in the correct group, i.e. dba on UNIX, if you are not in the correct group then this wont let you in.

To stop anyone doing it you can set something in the init.ora file, forget what it is off hand, will look it up.