How to Do an IT Security Audit
Understanding your business will focus your efforts.
Computerworld - If you're the IT manager at a small to midsize business, it's only a matter of time until you're asked to do an IT security audit. Even in a larger company, if security is decentralized, you may be the go-to guy in IT. You're neither a security expert nor an auditor, and resources are tight. How will you begin and where will you go from there?
First, don't panic. "People sell themselves short," says Jay M. Williams, senior vice president and chief technology officer at The Concours Group, an IT consulting firm in Kingwood, Texas. "For the most part, security is common sense."
Join a security research organization such as the Information Security Forum, says RA Vernon, chief security officer at Reuters America Inc. in New York. "You'll find a group of individuals willing to talk about security issues, share experiences and add some value to any process you may try to implement," he says. They can direct you to software, methodologies and other resources to help you tackle the job.
Consult with your business executives to be sure you understand which aspects of your business are most vulnerable to security threats.
Consider your industry. "Too often people think they have to create Fort Knox," Williams says, but in reality, few companies have extremely tight data security requirements. "If you're in the nuclear power business, you're right at the top," he says. "But if you're in baked goods, nobody's looking to knock off the Keebler elf."
Manage executive expectations. "An IT audit program will not happen overnight," says David Hoelzer, director of Global Information Assurance Certification and manager of the Advanced Systems Audit track of the SANS Institute, a cooperative security research and education organization in Bethesda, Md. Depending on the size of the organization, it will take at least several weeks, he says. "Prepare management for the work that will be required of them to assist you," he adds, because they'll need to help correct any faulty policies and practices that are uncovered.
Map it out. Work with technology and business analysts to draw a high-level schematic of the vulnerable intersections of technology and business, Vernon suggests.
Consider security tools. There is software that can scan your network and produce a list of areas of exposure. There are also tested methodologies such as OCTAVE from the CERT Coordination Center at Carnegie Mellon University in Pittsburgh that help you build a security program to industry standards. Your colleagues in the security group can help


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Practice Management: Double Billing Rate and Improve Patient Services
- Would you like to double your billing rate and achieve faster payment for services?
Download this customer success story to see how One Health... - Mission Critical Data Explosion and Customer Case Study
- Would you like to double your tier 1 storage capacity while simultaneously reducing your storage footprint?
Download this customer success story to see how... - Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios
- Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.
- Database Activity Monitoring Is Evolving
- Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.
- Establishing a Strategy for Database Security is No Longer Optional
- The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three...
- Live Webcast
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute - Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT
In a recent study conducted by Ponemon Institute, fifty-five percent of respondents... - Live Webcast
A Geek's Guide to Presenting to Business People - Live Webcast: Wednesday, June 20th at 1:00 PM EDT
Join this live webinar with Paul Glen, author of Leading Geeks, to learn how to... - Live Webcast
Today's NAS: A Solution Beyond Old Limits - Date: Tuesday, July 17, 2012 2:00 PM EDT
Traditional NAS systems don't scale beyond fixed limits. Proliferation of NAS systems leads to management... - Distributed Database Security with Real-time Monitoring
- View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
- InfoSphere Warehouse Packs Demo
- These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
- Delivery Management -- Extending Lifecycle Management
- Date: Wednesday, June 20, 2012, 1:00 PM EDT
Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,... - Leverage automation today to reduce IT complexity
- Date: Tuesday, June 5, 2012, 2:00 PM EDT
Whether your B2B complexity is caused by multiple technologies due to M&A, business or application specific... - Redefine Expectations in the Data Center
- Need to do more with less? Watch this video to learn how HP ProLiant Gen8 servers can help your business deploy servers three...