unhappyghost

Guide to ‪#‎Security_Audits‬

Jul 23rd, 2013
61
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.97 KB | None | 0 0
  1. Guide to ‪#‎Security_Audits‬
  2. -----------------------------
  3. What you need to know about internal and external security checkups.
  4.  
  5. The security audit is a practice that could best be filed under the "necessary evil" category. While no business owner, executive or IT manager relishes the thought of enduring an end-to-end security examination, it's generally understood that an audit is the best and only way to fully ensure that all of a business's security technologies and practices are performing in accordance with established specifications and requirements.
  6.  
  7. Security audits are typically conducted for the purposes of business ‪#‎information_security‬, ‪#‎risk_management‬ and ‪#‎regulatory_compliance‬. If performed correctly, a security audit can reveal weaknesses in technologies, practices, employees and other key areas. The process can also help companies save money by finding more efficient ways to protect IT hardware and software, as well as by enabling businesses to get a better handle on the application and use of security technologies and processes. As bothersome as security audits are, business owners, executives and IT managers who truly understand them realize that periodic examinations can actually help ensure that ‪#‎security_strategies‬ are in sync with overall business activities and goals.
  8.  
  9. ‪#‎Audit_Practices‬ and Activities
  10. --------------------------------
  11. There is no standard security-audit process, but ‪#‎auditors‬ typically accomplish their job though personal interviews, ‪#‎vulnerability_scans‬, examination of OS and security-application settings, and ‪#‎network_analyses‬, as well as by studying historical data such as ‪#‎event_logs‬. Auditors also focus on the business's ‪#‎security_policies‬ to determine what they cover, how they are used and whether they are effective at meeting ongoing and ‪#‎future_threats‬.
  12.  
  13. ‪#‎CAATs‬ (‪#‎Computer_Assisted_Audit_Techniques‬) are often employed to help auditors gain insight into a business's ‪#‎IT_infrastructure‬ in order to spot potential ‪#‎security_weaknesses‬. CAATs use system-generated ‪#‎audit_reports‬, as well as ‪#‎monitoring_technology‬, to detect and report changes to a system's files and settings. CAATs can be used with desktop computers, servers, ‪#‎mainframe_computers‬, ‪#‎network_routers‬ and switches, and an array of other systems and devices.
  14.  
  15. While CAATs can provide definitive data on business systems, auditors must also keep an eye on activities and practices that are not easily quantifiable. Some of the key questions that an auditor must ask include:
  16.  
  17. -Who is in charge of security, and who does this person report to?
  18. -Have ‪#‎ACLs‬ (‪#‎Access_Control_Lists‬) been placed on network devices to control who has access to shared data?
  19. -How are passwords created and managed?
  20. -Are there audit logs to record who accesses data?
  21. -Who reviews the audit logs, and how often are they examined?
  22. -Are the security settings for OSes and applications in accordance with accepted industry security practices?
  23. -Have unnecessary applications and services been purged from systems? How often does this task take place?
  24. -Are all OSes and applications updated to current levels?
  25. -How is backup media stored? Who has access to it? Is it up-to-date?
  26. -How is ‪#‎email_security‬ addressed?
  27. -How is ‪#‎Web_security‬ addressed?
  28. -How is ‪#‎wireless_security‬ addressed?
  29. -Are remote workers covered by security policies?
  30. -Is a ‪#‎disaster_recovery‬ plan in place? Has the plan ever been rehearsed?
  31. Have custom applications been tested for ‪#‎security_flaws‬?
  32. -How are configuration and code changes documented? How often are these records reviewed?
  33.  
  34. Many other questions pertaining to the exact nature of the business's operations also must be addressed.
  35.  
  36. Auditors
  37. -----------
  38. An auditor's skills and affiliations depend on the nature of the audit and the audited company's business focus. An internal audit will usually draw auditors from within the business's own IT and accounting departments. Alternatively, a company may hire a ‪#‎security_consultant‬ to handle the job. A financial institution or other business working in a regulated industry will often find itself dealing with federal and state regulators. Auditors may also be sent to a business by private standards-setting bodies and other industry organizations.
  39.  
  40. Aftermath and Follow-Up
  41. ----------------------------
  42. Shortly after the audit concludes, the auditors will usually brief a company's owners, executives and managers on what they've discovered and if any immediate remedial action is necessary. A few days or weeks later, the auditors usually issue a formal report. Stakeholders can use both the meeting and the report as opportunities to gain insight into their security practices and make improvements.
  43.  
  44. While a security audit is usually a specific event, IT security is an ongoing process. As a business designs, deploys and maintains its security policies, technologies and practices, it should strive to maintain a constant state of preparedness that will allow it to pass a security audit at any given moment.
  45. #UnhappyGhost
  46.  
  47. .
  48.  
  49. ##############################################################
  50. # ṲИℋÅℙℙУḠ♓☮$✝ #
  51. ##############################################################
  52. || Website --------> http://unhappyghost.com/ ||
  53. || Facebook -------> https://www.facebook.com/unhappygh0st ||
  54. || FB Page --------> https://www.facebook.com/geeksch00l ||
  55. || Twitter --------> https://twitter.com/unhappygh0st ||
  56. || Google+ --------> http://goo.gl/WCHeJR ||
  57. || Youtube --------> http://goo.gl/A3mQIE ||
  58. || IPv6 Vids ------> http://goo.gl/Rbcxk ||
  59. || IPv6 Event -----> http://goo.gl/TaeXv ||
  60. ##############################################################
  61.  
  62. .
Advertisement
Add Comment
Please, Sign In to add comment