Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

What Can I Expect in a Security Audit ? 2

Status
Not open for further replies.

JohnBates

MIS
Feb 27, 2000
1,995
US
Hi everyone,

We have Fortune 500 client who will visit our office soon to conduct a "Security audit".

I would like to hear from anyone that has "survived" a security audit. What kinds of things do I need to be prepared for? Will they actually do hands-on investigating of the database? What was the outcome of your audit.... did they give you a detailed report ? did they shoot the DBA :)

Thanks, John
 
I survived a SAS70 audit. It was bloody, but I made it. It depends on how smart your auditor is. My auditor was checking everything from strength of passwords to who has access to the 'sa' account. Either way be prepared for them to tear everything apart looking for security weeknesses. They actually had me run traces.

Here is a tool from Microsoft that checks for best practices. It will help you make sure the obvious is OK.


- Paul [batman]
- If at first you don't succeed, find out if the loser gets anything.
 
We JUST had a security scan done on our production server. The things we had to change and look out for were the following:

encrypted SSNs
encrypted passwords
inactive accounts
correct permissions (based on company policy)

Hmm, I guess these were the only SQL things I can think of off my head.

[monkey][snake] <.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top