All the latest UK technology news, reviews and analysis

Sans offers tips for IT audit survival

by Shaun Nichols

18 Aug 2009

Be the first to comment

  • Tweet this
Security padlock
Third-party security audits need not be a nightmare

Enterprise IT managers need not dread third-party security audits, according to researchers at security firm Sans, which has published a list of tips to help IT departments get through audits with minimal headaches.

Companies are urged not to panic prior to an audit, to be prepared and to have possible questions answered in advance. Sans also recommended that administrators keep copies of security training materials and IT security policies handy.

Other tips include paying careful attention to logging, and keeping an untouched workstation on hand for the auditors to browse.

Most important, however, is maintaining the right attitude, according to Sans handler Mari Nichols. IT departments should approach audits not as a dreaded chore, but as a learning experience and a chance to beef up security protection.

"Playing these situations to your fullest abilities will not only increase the profitability of your business, it will result in a tightened down security posture for your company," she said.

"This may be the straw that increases security in your environment. You may even get your pet project going again after frustrating funding delays."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

34%

1%

11%

54%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Global Project/Programme Manager-with recruitment deployment experienc

My London client is looking for an experienced Programme...

PHP Developers (All Levels)

My leading client is looking for a number of excellent...

Group Services Manager - Telecoms

My client, a leading international name in Manufacturing...

Automated PHP Developer

My client is looking for an Automated Engineer/Developer...

To send to more than one email address, simply separate each address with a comma.