Does Audit Make Us Secure?  Presented at ISACA SV Spring Conference, May 15th, 2015 - (I totally stand by the content.). Presented by Robin Basham, M.Ed., M.IT, CISSP, CISA, CRISC, CGEIT, HISP, CRP, VRP, Founder EnterpriseGRC Solutions. Companies that passed the audit and had a major breach could have survived with this approach. 

March 18, 2015 “Three weeks before hackers infiltrated Premera Blue Cross, federal auditors warned the company that its network security procedures were inadequate.”

The Heartland intrusion began in May 2008, even though the company had passed multiple audits, including one conducted on Apr. 30. At the time, the Princeton (N.J.) company was in compliance with industry standards for data security, Carr says. Still, shortly afterward, 13 pieces of malware that capitalize on weaknesses in Microsoft (MSFT) software infiltrated one or more network servers.

"We get pinged 200,000 times per day by people trying to hack into our system," Carr says. "You do everything you can to make sure one of those pings doesn't get through, and we thought we had done everything we could do."

  • Does audit make us secure?
  • Why not?
  • Is it just me?
  • “Scope” implies permission for less secure practices on lower impact systems
  • We audit what we understand and miss the most important areas of security risk 
  • We expose a wide range of people to known areas of weakness
  • We distract people from their core responsibilities
  • We create a false sense of security by underrepresenting complex and broken processes
  • Did I Pick the Right form of Risk Assessment?
  • Is our goal to determine if we are secure?
  • Is our goal is to enable a more secure enterprise?
  • Are we expected to engage business partners, to provide meaningful metrics, to inform choices and decisions?
  • Does the organization account for security responsibilities across all areas of IT service?
  • Effective security & information management practices extend beyond audit

Gang Audit 

Main Menu