CHAPTER 9

Compliance Within the Workstation Domain

COMPLYING WITH SECURITY-RELATED REGULATIONS, legislation, and other requirements means ensuring your organization protects the security of your information. In most cases, ensuring information security means ensuring users take appropriate actions and refrain from inappropriate actions. Although the directive seems simple, implementing it can be complex.

If all users were perfect and completely compliant, there wouldn’t be a need to consider any further security layers. Remember that users include both authorized and unauthorized users. Attackers fall into the category of unauthorized users. Because users are imperfect and often noncompliant, you must include additional layers of security controls ...

Get Auditing IT Infrastructures for Compliance, 2nd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.