IT Security Audits News
September 18, 2015
An internal audit of the U.S. Department of Homeland Security has been completed, detailing areas where its cyber mission has failed and what plans are in place to make improvements.
August 12, 2014
Discussing the state of PCI DSS compliance, Gartner's Avivah Litan says the industry still struggles with PCI auditors who both identify PCI problems and sell remediation services to fix them, causing a conflict of interest.
October 31, 2013
A veteran QSA believes PCI DSS 3.0 will help both QSAs and enterprises, but says further clarifications are needed to avoid PCI assessment disputes.
July 25, 2012
Don Weber of InGuardians is releasing his smart meter hacking tool, but only to utilities, vendors and vendor-vetted researchers.
IT Security Audits Get Started
Bring yourself up to speed with our introductory content
Here are some important criteria for hiring a partner to review your information security program, with a focus on HIPAA and HITECH compliance. Continue Reading
The long-awaited HIPAA audits conducted randomly by HHS are finally supposed to happen in 2015, but with stricter requirements. Here's how organizations can get ready. Continue Reading
NASA recently released a cloud computing audit report with best practices enterprises can use to assess and improve their cloud governance practices. Continue Reading
Evaluate IT Security Audits Vendors & Products
Weigh the pros and cons of technologies, products and projects you are considering.
Gartner analyst Avivah Litan discusses how Gartner clients are reacting to the changes in PCI DSS 3.0, and whether the increased rigor in the standard will prove beneficial to enterprises. Continue Reading
Peter G. Neumann shares his thoughts on the inherent complexity of trustworthiness and the evolutionary promise of clean-slate architectures. Continue Reading
Moving to a cloud environment brings compliance challenges, but they’re not insurmountable. Continue Reading
Product ReviewsPowered by IT Central Station
Powered by IT Central Station
Valuable Features: I like the distributed model of IT360 like the central and probe model. • Improvements to My Organization: An...Continue Reading
It's not only taken over asset and inventory management, but it also has the ability to function across departments. However, some of the reporting metrics could be improved for more granularity.Powered by IT Central Station
Valuable Features: Asset tracking and inventory management, service desk solutions - incidents and self-service portal - and service catalogs...Continue Reading
We're able to provide Process as a Service, but the usability and user experience is a really big issue and needs to be improved.Powered by IT Central Station
Valuable Features: Its integrated process data-model is a feature that's valuable for us. • Improvements to My Organization: It's...Continue Reading
Manage IT Security Audits
Learn to apply best practices and optimize your operations.
Learn about a potential audit concern when transitioning from a traditional firewall to a next-generation firewall. Continue Reading
Expert Mike Chapple explains how two descoping techniques can help many organizations reduce their regulatory compliance burden. Continue Reading
One QSA offers pre-audit planning advice to ensure a smooth, successful enterprise IT security audit for both the organization and the auditor. Continue Reading
Problem Solve IT Security Audits Issues
We’ve gathered up expert advice and tips from professionals like you so that the answers you need are always available.
The annual FISMA audit is designed to ensure companies need to have consistent security standards. Here's how to prepare for the audits. Continue Reading
There are several risks involved when using end-of-life software, including the possibility of compliance violations. Expert Mike Chapple explains. Continue Reading
Documentation is a key requirement for many IT security regulations. Expert Mike Chapple offers tips for maintaining documentation the right way. Continue Reading