Baseline 291
Has the monetary or prestige loss been calculated?•
What elements of the organization have been compromised?•
What security tools are operational?•
Who have been the perpetrators?•
Where did the attacks originate?•
Appendix A provides a guide for conducting such a security audit. It is essential that all
computer and network assets be afforded some level of protection. These assets include the
building, equipment rooms, wiring closets, computer and network devices, storage devices,
software, and documentation.
Computer Security Audit
A computer security audit is a manual or systematic measurable technical assessment of a
system or application. Manual assessments include interviewing staff, performing security
vulnerability sc ...