Security audits in mixed environments

Dario Valentino Forte · Network Security · 2009

Security audits are now part of the regulatory landscape for many organisations, and it becomes particularly important when dealing with third party providers such as outsourcers. Service contracts must be complemented by documentation clearly explaining the nature of such audits, and the expectations from them. Under such agreements, individuals within the customer and the outsourcing provider must understand the role is that they play in supporting such security audits. Making reference to best practices and international standards, Dario Forte examines the assignment and control procedures for outsourcer authorisation profiles, assessing their potential impact on data confidentiality, integrity and availability and on service levels, identifying potential weaknesses in control measures and the corresponding corrective actions that should be taken. Laws in various countries require multi-level audits, especially for information systems managed wholly or partially via service contract with outsourcers. The documentation describing the logical security controls and methodology for protecting data integrity in the context of such services comprises a series of annexes to the service contracts, as well as a security manual which is usually necessary for setting forth policies and procedures. Both company and outsourcer personnel must be assigned authorisation profiles that are appropriate to their roles in the provision of service.

Read the paper · More papers on PaperTik