IT Audit Coming Up? Here's What You Need to Include
Have you conducted an audit of your IT Environment?
According to best practices, security gurus and regulators, there are many
different areas of your organization that should be reviewed on a periodic
basis.
This list is not exhaustive, but will give you a great start:
External Security Audit – A scan of the
vulnerabilities associated with systems connected and
accessible from the Internet. In addition, a passive penetration of the
vulnerabilities and their risk to your network environment.
Internal Security Audit - An extensive scanning process on all key systems internal
to the environment.
Audit Network Operating System Security - A detailed look at the design, implementation,
administration, and monitoring of servers and systems
Audit Security Policies - A streamlined way to ensure your companies Information
Security Polices are in sync with industry standards
Audit Firewall Security - A
detailed review of the Firewall the IDS/IPS system(s) to
ensure proper design, implementation, administration, and monitoring.
Audit AntiVirus Protection - A detailed review that
your antivirus protection is properly designed,
implemented, administered, and monitored as necessary to not only protect
against common viruses, but to protect against additional security threats that
could create a backdoor to corporate systems and/or cause denial-of-service
outages.
War-dialing / Telco Testing -
A scan of
every phone assigned to your organization, determines if a modem exists,
determines the type of system used to accept the call, evaluates authentication
mechanisms, and performs a passive penetration attempt on the device.
Wireless Audit – identify any weaknesses and
demonstrate best practice methods for design and implementation
Workstation Vulnerability Testing -
A scan for workstation vulnerabilities that hacking tools
and viruses can take advantage of to gain control of the workstation and launch
larger attacks. The workstation is also scanned extensively for spyware,
malware, Trojans, key-loggers, and other harmful software.
Social Engineering Evaluation - A test of your internal
users to determine if they will divulge sensitive information about
systems and/or user-accounts to unauthorized individuals
when approached with a cleverly crafted dialog by an outsider to the
organization.
If you would like further information regarding an IT
Audit, please feel free to contact BAI Security.
|