Thursday, October 7, 2010
Sunday, September 19, 2010
IT Audit and IT Security Audits: Is There a Difference?
Posted by David Hoelzer on November 10, 2009 – 5:37 pm
Filed under Compliance, Security, Standards
Last week I had an interesting conversation with some principals in one of the Big Four. We were discussing some upcoming plans that we have for creating a course to assist non-IT folks to transition into IT Audit in addition to assisting non-Audit folks to take on more of an audit role.
During the conversation, we were asked by one person, “Well, are you teaching IT Audit or are you teaching IT Security Audit?” What an interesting question, we thought. We went on to explain our point of view.
The purpose of IT Audit is to ensure that all of the controls are functioning correctly to meet the objectives of the business. This includes operational matters like user creation process, active directory management, group policy settings, firewall configurations, router infrastructure configurations, etc. Almost all of the controls in IT today include security settings. In our view, there is no sense auditing these items to verify that the settings match the policies unless you are also validating that the processes governing the policies are correct.
In other words, if your IT Audit isn’t validating that, in addition to operating correctly, your organization is correctly applying security principles and controls, what exactly are you auditing??? The folks we were speaking with, fortunately, seemed to agree that this was the correct view even though they had posed the original question. It does give us pause to wonder, however.
For example, consider the recent findings regarding FISMA, specifically the notion that FISMA has failed because the IT auditors who are doing the evaluations have been tasked with verifying that everyone is doing what NIST says in terms of procedures without any consideration for where the actual risks are to the business!
This is also precisely the reason that Sarbanes-Oxley has language requiring that the IT systems support the accuracy of the financial results. In the past I have railed against the lack of specificity in Sarbanes-Oxley, but given what’s happened with FISMA it makes me wonder if it might be better in some respects.
In the end, determining the best strategy or standard to use to ensure security will always be a task best done as a retrospective, but it seems safe to say that the “right” answer falls somewhere between too much and too little. Like Goldilocks, we’re all looking for the “Just Right” level of detail in standards, forcing organizations to develop well thought out controls that connect to business and security objectives!
For a comprehensive course on how to identify critical controls, validate that the correct controls are in place and validate processes, consider the SANS 6 day course, “Advanced System & Network Auditing“. David Hoelzer is the SANS IT Audit Curriculum Lead and the author of several SANS IT Audit related courses.
Filed under Compliance, Security, Standards
Last week I had an interesting conversation with some principals in one of the Big Four. We were discussing some upcoming plans that we have for creating a course to assist non-IT folks to transition into IT Audit in addition to assisting non-Audit folks to take on more of an audit role.
During the conversation, we were asked by one person, “Well, are you teaching IT Audit or are you teaching IT Security Audit?” What an interesting question, we thought. We went on to explain our point of view.
The purpose of IT Audit is to ensure that all of the controls are functioning correctly to meet the objectives of the business. This includes operational matters like user creation process, active directory management, group policy settings, firewall configurations, router infrastructure configurations, etc. Almost all of the controls in IT today include security settings. In our view, there is no sense auditing these items to verify that the settings match the policies unless you are also validating that the processes governing the policies are correct.
In other words, if your IT Audit isn’t validating that, in addition to operating correctly, your organization is correctly applying security principles and controls, what exactly are you auditing??? The folks we were speaking with, fortunately, seemed to agree that this was the correct view even though they had posed the original question. It does give us pause to wonder, however.
For example, consider the recent findings regarding FISMA, specifically the notion that FISMA has failed because the IT auditors who are doing the evaluations have been tasked with verifying that everyone is doing what NIST says in terms of procedures without any consideration for where the actual risks are to the business!
This is also precisely the reason that Sarbanes-Oxley has language requiring that the IT systems support the accuracy of the financial results. In the past I have railed against the lack of specificity in Sarbanes-Oxley, but given what’s happened with FISMA it makes me wonder if it might be better in some respects.
In the end, determining the best strategy or standard to use to ensure security will always be a task best done as a retrospective, but it seems safe to say that the “right” answer falls somewhere between too much and too little. Like Goldilocks, we’re all looking for the “Just Right” level of detail in standards, forcing organizations to develop well thought out controls that connect to business and security objectives!
For a comprehensive course on how to identify critical controls, validate that the correct controls are in place and validate processes, consider the SANS 6 day course, “Advanced System & Network Auditing“. David Hoelzer is the SANS IT Audit Curriculum Lead and the author of several SANS IT Audit related courses.
Thursday, September 16, 2010
Sunday, August 22, 2010
Friday, August 20, 2010
The Massachusetts Data Protection Law
sponsored by SearchSecurity.com & SearchCompliance.com
Regulatory compliance can be a challenging task for any corporation, but it can be particularly onerous if the regulation is a moving target. This is the case with Massachusetts data protection regulation 201 CMR 17.00, which seemed ready to go into effect Jan. 1, 2010 (already delayed once from a May 2009 enforcement date). Just a few months ago, this state regulation was positioned as a game changer. It framed data privacy in a way that forced organizations to take steps to protect personal data.
Today most state privacy laws focus on notifying people of a data breach rather than protecting the information in the first place. MA 201 CMR 17.00 was proactive, rather than reactive, security. But due to the uncertain economy, costs associated with meeting the regulations and complaints from the public, businesses and organizations, the Massachusetts Senate is now considering weakening the scope and specifics of the regulation.
But in a legislatively aggressive climate such as we are in now, with new security exploits being discovered every day and data breach disclosures such as those from The TJX Cos. and Heartland Payment Systems Inc., strict privacy and data protection laws from the state and federal levels are inevitable. Simply stated, MA 201 CMR 17.00 is good security practice. So despite the near-term uncertainty about the particulars, the prudent move by corporate IT is to take steps now to be ready for tough encryption and policy statements later.
Massachusetts businesses facing down MA 201 CMR 17.00 can meet the challenge with preparation and execution. The first step to preparation is education. Read this e-book to learn more about important topics such as identity theft, prevention of breaches, mandatory encryption, and getting ahead of the game where Massachusetts data protection law is concerned.
Sponsored By: BeCrypt, GuardianEdge, Lumension, Razorpoint Security Technologies, Sophos, and CDW
Regulatory compliance can be a challenging task for any corporation, but it can be particularly onerous if the regulation is a moving target. This is the case with Massachusetts data protection regulation 201 CMR 17.00, which seemed ready to go into effect Jan. 1, 2010 (already delayed once from a May 2009 enforcement date). Just a few months ago, this state regulation was positioned as a game changer. It framed data privacy in a way that forced organizations to take steps to protect personal data.
Today most state privacy laws focus on notifying people of a data breach rather than protecting the information in the first place. MA 201 CMR 17.00 was proactive, rather than reactive, security. But due to the uncertain economy, costs associated with meeting the regulations and complaints from the public, businesses and organizations, the Massachusetts Senate is now considering weakening the scope and specifics of the regulation.
But in a legislatively aggressive climate such as we are in now, with new security exploits being discovered every day and data breach disclosures such as those from The TJX Cos. and Heartland Payment Systems Inc., strict privacy and data protection laws from the state and federal levels are inevitable. Simply stated, MA 201 CMR 17.00 is good security practice. So despite the near-term uncertainty about the particulars, the prudent move by corporate IT is to take steps now to be ready for tough encryption and policy statements later.
Massachusetts businesses facing down MA 201 CMR 17.00 can meet the challenge with preparation and execution. The first step to preparation is education. Read this e-book to learn more about important topics such as identity theft, prevention of breaches, mandatory encryption, and getting ahead of the game where Massachusetts data protection law is concerned.
Sponsored By: BeCrypt, GuardianEdge, Lumension, Razorpoint Security Technologies, Sophos, and CDW
Thursday, August 19, 2010
Subscribe to:
Posts (Atom)