Security - CIOInsight
Home arrow Security arrow 10 Things the Security Auditor Saw

Security Slideshow:
10 Things the Security Auditor Saw

By Bob Violino on 2009-02-09


by Bob Violino

Deloitte's 6th Annual Global Security Survey shows the top priorities and problems revealed by internal and external audits.


LATEST STORIES

BLOGS
 
  • of
Excessive access rights. Almost one-third of respondents cited this finding, making it the top response. Individuals should have rights only to information needed to perform their jobs, and those should be revoked when no longer needed they.

Segregation of duties. Users shouldn't have access to responsibilities and functions that conflict with one another. Lack of segregation of duties might allow people to circumvent controls.

Access control compliance with procedures. Access control ensures that users have access only to the systems and information they need to properly do their jobs.

Lack of audit trails/logging. With regulatory compliance a key part of risk management, organizations need to have the proper trails and logging procedures in place.

Lack of documentation of controls. Compliance means having documentation that the proper controls are in place.

Excessive developers' access to production systems and data. Make sure application developers have appropriate access to production systems and data, and determine the risk if they have too much.

Lack of review of audit trails. Audit trails must be reviewed on a regular basis, and updated as needed.

Lack of clean-up of access rules following a transfer or termination. Access rules need to be revoked or changed when someone leaves the organization or is transferred. Failure to do this can result in damaging security breaches.

Use of production data in testing. Testing of systems and applications shouldn't involve production data, as this could introduce security risks.

Disaster recovery plan/business continuity plan testing. Have disaster recovery and business continuity plans been tested adequately? Organizations can't afford to risk extensive systems downtime and lost business.

  • More slideshows

FEATURED SPONSORED VIDEOS

FEATURED SPONSORED ARTICLES

Erasable E-Paper Saves Trees, Cuts Costs

Why Smart Companies Should Adopt the Lessons of Gaming

Interest in Mobile WiFi Hotspots Fuels New Solutions

A Closer Look at Public Cloud Security

View More Articles

  Brought to You By
Click Here



 

Advertisement

Sponsored Links
  • Get up and running in as quickly as 30 days with BI. Learn how today.

  • FREE Securing Smartphones & Tablets for Dummies Book from Sophos
  • 77% of the Fortune 500 Manage Content Securely with Box.
  • Leverage your virtual computing environment with Dell.
  • Build an IT Infrastructure That Delivers the Future
  • 5 New Technologies That Will Change Enterprise ITAdvertisement
  • eWEEK Quick LInks