BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

Playing Russian Roulette With Your Auditor

Posted May 20, 2011    Peter McCalister

Who could forget the image of Christopher Walken’s Academy Award winning performance in The Deer Hunter? Anyone who has seen that movie can not help but understand the ultimate penalty for losing at Russian Roulette. Even though the penalties aren’t quite as “life threatening” when the compliance auditor comes around, they can be “career threatening” to the IT executive who plays the same game with meeting regulatory requirements.

I’ve blogged before about the right side, wrong side and wild side of the dreaded audit, but I didn’t realize the extent of IT organizations that “pray for the best” when it comes to achieving a passing mark from their outside auditors. The misuse of privilege in any organization is absolutely in violation of most every regulation on the books today. Just run an entitlements report to see who has access to what information resources across your extended enterprise and you will immediately determine to extent of the potential problem. For those of you more interested in digging to the heart of the challenge, then I found this very cool mind-map on the “Frequently Avoided Questions About IT Auditing” in New Zealand of all places.

It also helps to understand the Information Technology Audit Process. The Committee of Sponsoring Organizations of the Treadway Commission (COSO) is recognized worldwide for providing guidance on critical aspects of organizational governance, business ethics, internal control, enterprise risk management, fraud and financial reporting and has an incredible amount of content on their site to assist with this as well.

Bottom line: don’t play Russian Roulette with your auditor as the consequences can get messy.

Leave a Reply

Additional articles

red-thumbprint

Why big data breaches won’t always be so easy

Posted September 19, 2014    Byron Acohido

This blog post is republished with the permission of ThirdCertainty. See the original post here. – By: Byron Acohido, Editor-In-Chief, ThirdCertainty Some day, perhaps fairly soon, it will be much more difficult for data thieves to pull off capers like the headline-grabbing hacks of Home Depot and Target. That’s not a pipe dream. It’s the projected outcome…

Tags:
, , , , ,
pbps-blog2

8 Reasons Your Privileged Password Management Solution Will Fail

Posted September 18, 2014    Chris Burd

Leveraging complex, frequently updated passwords is a basic security best practice for protecting privileged accounts in your organization. But if passwords are such a no-brainer, why do two out of three data breaches tie back to poor password management? The fact is that not all privileged password management strategies are created equal, so it’s critical…

Tags:
, , , , , ,
pbps-customer-campaign-image

You Change Your Oil Regularly; Why Not Your Passwords?

Posted September 11, 2014    Chris Burd

There are many things in life that get changed regularly:  your car oil, toothbrush and hopefully, your bed sheets.  It’s rare that you give these things much thought – even when you forget to change them. But what if you’re forgetting something that can cost you millions of dollars if left unchanged for long periods…

Tags:
, , ,