Leythos ( snipped-for-privacy@nowhere.lan) wrote: : In article , : snipped-for-privacy@financialdatacorp.com says... : > A third party "security auditor" (an employee from a CPA firm) was : > looking at the logs of ONE of their servers
: I think this is the third time I've seen someone mention an audit by a : CPA firm and I'm amazed that they can get away with it. CPA firms don't : exactly have shining security reputations, are known for billing clients : when not actually providing anything, and are a lot like lawyers :)
: I've yet to see an audit done my a CPA firm that did anything except : generate more billable hours for the firm.
It depends
Most public corporations have to have an annual external audit [as do non-profits]. Most of the large audit companies now also do audits of the IT systems used by the company.
If you go into this process with eyes open, the audit can be a very useful 2nd set of eyes on potential security risks. However, having been on the receiving side of this for over 20 years, you have to be aware that many of these auditors work off of a checklist based on 'best practices' which tend to be based on what their large corporate customers do. Be prepared to argue certain points if the 'best practice' does not apply to your organization.
[A good example is the collision between 'best practice' for a database system is found to not be running and the audit finding wants it done. The problem is that the database in question is part of a larger ERP application. The response we gave was that we would query the ERP vendor to see if there were any issues in following the recommendation and, if not, schedule the modification as part of the change control process]
Always have a meeting with the IS audit team prior to the start of work to go over the scope of work and the type of tests they will do. Work out the roadmap for the audit before it starts.
After it is completed, schedule meetings with the auditors to go over any findings and discus mitigation and/or objections to the findings with them. You also need to make your financial people aware of any issues and have a firm understanding that you will not blindly follow an auditor's recommendation just because it is a recommendation.