Analytical Audit Measures

As much as I would like to say that a single formulaic process could solve all auditing needs, there are other factors that must also be considered. The process discussed in the previous section simplifies 90% of the audit work and gives us accurate, consistent, and measurable results that can be obtained without a great deal of security experience. Some organizations have based their entire audit methodology on this type of process since it provides the greatest impact and requires the fewest security resources. After this process is completed, however, it is important to take a look at the aspects of security beyond the objects. What we need to do is examine at the organization as a whole, in light of the rules of ...

Get Inside the Security Mind: Making the Tough Decisions now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.