• Jump to Left Menu
  • Jump to Right Menu
  • Jump to Main Content
  • Jump to Footer
  • Accessibility Page
IT-Director.com Logo

 

Main navigation - go to a section of this website:

  • ARCHIVE
  • PAPERS
  • EVENTS
  • NEWSWIRE
  • BLOGS

  

Register For Membership | Member Login

 
 
DOMAINS
  • Enterprise
  • SME
  • Business Issues
  • Technology
  • Services
  • Channels
FEATURED EVENTS
  • London Evening Standard Business Connections Event, 'Use Technology to Boost Your Business'
    23rd May
    London, United Kingdom
  • 24th Annual FIRST Conference on Computer Security and Incident Response
    17th June - 22nd June
    Portomaso St. Julians, Malta
POPULAR PAPERS
  • Unifying electronic communications for enhanced security by Bloor Research
  • Data profiling: the business case by Bloor Research
USEFUL LINKS
  • Last 7 Days
  • Archives
  • Top Articles
SHARE THIS PAGE
  • Delicious Icon Delicious
  • Digg Icon Digg
  • reddit Icon reddit
  • Facebook Icon Facebook
  • StumbleUpon Icon StumbleUpon
CONTENT FEED

Sitewide
RSS Feed:

RSS Icon

What is RSS?

RANDOM QUOTE
Raw wit - "He was either a man of about a hundred and fifty who was rather young for his years or a man of about a hundred and ten who had been aged by trouble." - P.G. Wodehouse

PAGE TOOLS
RECENT POSTS
  • Organisations struggle to safely and securely delegate sys-admin tasks
  • Quocirca's Report from Infosecurity Europe 2012
  • Who wants sweaty assets?
  • Organisations aren't performing device configuration backups with the diligence that they should
  • Windows desktop admin rights - an open door for malware?
  • Reducing the number of sys-admin errors
BLOG ARCHIVE
  • May, 2012
  • April, 2012
  • March, 2012
  • February, 2012
  • December, 2011
  • November, 2011
  • October, 2011
  • September, 2011
  • August, 2011
  • July, 2011
  • April, 2011
  • February, 2011
Blogs > Quocirca

Avoiding (awful) bad practice at audit time

Bob Tarzey By: Bob Tarzey, Service Director, Quocirca
Published: 21st October 2011
Copyright Quocirca © 2011
Logo for Quocirca

Quocirca saw an estimate recently that IT security managers can spend as much as 30% of their time preparing for and delivering audits. This is mundane and uninteresting work and if it can be automated – all the better. However, recent Quocirca research, sponsored by sys-admin tools vendor Osirium, shows that less than 20% of organisations fully automate the gathering of data for audits and less than 10% automate the remediation of audit gaps.

What’s more, over 70% admitted that in some cases system administrators (sys-admins) made informal, uncontrolled changes to sys-admin procedures immediately prior to audits in order to meet the audit requirements, which then lapse following the audit, with 8% saying this was a regular practice. Obviously, this is extremely bad practice; if auditors uncovered the fact the procedures had been temporarily changed to satisfy them, then the audit would surely be failed anyway?

Osirium has published the research and some suggestions for achieving better practices as the first of its Alpha Files, a series of short reports on sys-admin, privileged user management and auditing practices. Quocirca will be publishing a new free report later in 2011 that will detail and analyse in detail all the new research.

Reader Comments

We have not received any comments against this entry. Why not be the first?

We automatically stop accepting comments 180 days after a post is published. If you would like to know more about this subject, please contact us and we'll try to help.

  • Contact
  • | Site Map
  • | Terms of Use
  • | Privacy Policy

Published by: Electronicdawn Ltd.
T: +44 (0)190 888 0760 | F: +44 (0)190 888 0761