Welcome CisForCookie, the newest member
New user?    Register    Login
http://www.attackprevention.com


Date Submitted: 08/25/05
Hits: 41
Rating: 00000 based on 0 votes

Case Study: Automating Common InfoSec Auditing Tasks on a Windows 2000 Network



Added by Papergrl

Description: Policies are only as good as the procedures used to implement them. When the procedures are too cumbersome or time-consuming, it is likely that policy compliance will suffer. Unrealistic procedures can lead to "implemented policies" that are weaker than the stated policies. Conversely, ensuring that procedures are easy to implement has the effect of making full policy compliance more likely. In this case study, we will examine how automating information security audit procedures at a university had the effect of increasing security through increased policy compliance. We will discuss three stated policies, their associated procedures, and how poorly designed procedures led to weak "implemented policies." We will then discuss how the procedures were automated, and, finally, discuss the effects of the automation on the university's overall security stance.

Read the Complete Paper



You don't have permission to post replies.

Please login or register.

Copyright 2008 AttackPrevention