Chapter 4. Integrity and security 73
4.2.3 Auditing
Auditing is the process of ensuring that the information processing system
(hardware, software, liveware, middleware, policies, and procedures) complies
with the installation security policy. Auditing may be:
A one-time project, such as a snap inspection, or
An ongoing process, pursuant to policies
The two types of information security audits can be termed preemptive and
reactive. As their names indicate,
preemptive audits test security controls, and
reactive audits respond to potential security breach events. Incident Response is
an integral part of the security management plan.
Some companies resist implementing information security controls because they
believe the costs are prohibitiv ...