Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 47 guests and 2 members online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Otherarrow Auditing Standards
EH-Net
May 23, 2013, 01:39:34 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Auditing Standards  (Read 3874 times)
0 Members and 1 Guest are viewing this topic.
oleDB
Recruiters
Full Member
*
Offline Offline

Posts: 236



View Profile WWW
« on: November 17, 2006, 09:04:16 AM »

I've never worked as an auditor, however I've been participant to several SOX and PCI audits. One thing that I never understood correctly was all the various frameworks and how they overlapped. I listened to a presentation on audits last night and couldn't get a straight answer from the presenter either, so I decided to start googling. This is what I found

-COBIT For IT Governance And Control
-ITIL For Service Delivery And Support
-ISO 17799 For Security Mgmt


This document lays it out in exstensive detail
http://www.itsmf.com/images/news/ITIL-COBiT.pdf

 
Logged
don
Editor-In-Chief
Administrator
Hero Member
*****
Online Online

Posts: 4167


Editor-In-Chief


View Profile WWW
« Reply #1 on: November 17, 2006, 11:29:34 AM »

I'm not an auditor, but here's what I've come to understand:

One thing to keep in mind when it comes to regulations like SOX and HIPAA is that, although they are the law, they are very vague when it comes to details on how exactly to accomplish certain goals. The frameworks are sets of guidelines that are not set in stone or required by law. So what most companies do is pick and choose from each one and make a policy that suits their business. Once they have their own in written form, that becomes the baseline they use for dealing with audits.

Here's an example that will make your head spin. For lack of a good analogy, let's just use a numbering system with 100 being perfect. If Company A sets their goal as 75 but only reach 65 while Comapny B sets their goal at 45 and attains 50, who passes an audit?

Since Company A has an overall higher score, one would think Company A did better in their audit. Not so. Company A would fail while Company B would pass with flying volors. It's all based on the goals you set for yourself. It's almost like having to choose wireless plans with the right amount of minutes.

Go figure.

Then again, this is a maturing field, and I'm sure wrinkles will be worked out eventually. At least it has us all thinking about security, and that's a good thing. So, although clearly not a perfect system, it's better than nothing.

Don

PS - Please correct me if I'm wrong.
Logged

CISSP, MCSE, CSTA, Security+ SME
don
Editor-In-Chief
Administrator
Hero Member
*****
Online Online

Posts: 4167


Editor-In-Chief


View Profile WWW
« Reply #2 on: November 26, 2006, 09:21:07 PM »

Although not specifically for security, the IT Infrastructure Library (ITIL) is a framework for constructing efficient systems. In it's current edition, it contains 9 volumes down from 44 in the late 80s and early 90s. Here's a really good intro article to ITIL in PDF format from InfoWorld:

ITIL Crash Course

Look for ITIL v3 sometime in mid-2007.

Hope this helps,
Don
Logged

CISSP, MCSE, CSTA, Security+ SME
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.11 seconds with 24 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.