Home > Security Tips > Compliance Counselor > Security and audit relationships: Uneasy antagonists or partners in arms?
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

COMPLIANCE COUNSELOR

Security and audit relationships: Uneasy antagonists or partners in arms?


Tony Higgins, Contributor
12.16.2008
Rating: -3.75- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


For more information
Read about the latest efforts to develop a common logging and audit standard.

Learn best business practices for Unix audit settings.

Preparing for a network security audit? Learn steps for monitoring and remediation.
Information security professionals are often challenged by a strained relationship with internal audit staff and the organization's external auditors. When specialized assessors, such as Qualified Security Assessors (QSAs), are added to the mix, things can go from bad to worse. However, security professionals have much to learn -- and to gain -- by getting into the heads of the people who serve in these roles.

The most important thing to remember about an IT auditor is that he or she focuses on a few simple questions:

  • For each area of risk, has the organization either accepted the risk or identified an appropriate control?
  • For each control, where is the evidence that it works as intended?
  • Is there documentation that all actions were carried out in the intended manner with required oversight and approval?

Therefore, there are a few simple things security leaders can do to streamline the interactions between the security team and the auditors:

  • Document not only measures to reduce risks, but also those cases where the organization decides to accept risks, in return for greater flexibility or potential benefits.
  • Embed the idea of "controls" and "control objectives" in the security architecture. Controls are the specific measures put in place to ensure compliance or security, and control objectives are the metrics or evidence that the control is working as intended. For example, a control might be procedures for disabling the IDs of terminated staff, and the control objective would then be that all access is removed within two business days of termination.
  • These are key concepts everyone needs to use, and they will improve security by taking hazy best practices and turning them into measurable performance metrics.
  • Never overstate or underestimate the degree of confidence you have in your controls and mitigations. If you can't prove that, for instance, access rights are being removed in a timely way and in practical terms, your credibility will be reduced for this and other controls. In simple terms, if the auditor finds an exaggeration in the effectiveness of one area, all the other areas will be called into question.

In my experience, auditors appreciate it when their jobs are made easier. One helpful approach is to fully document the mapping of the security policy and architecture to a standard framework, such as COBIT or the ISO 27000 series. When the auditor walks in and says, "How are you dealing with encryption key management issues?," it will be invaluable to know that the criteria he will use are described in COBIT "Deliver and Support" section 5.8; it will be evident what the auditor is likely to assess.

Talk to the internal audit team during the company's annual security policy and status review and get a feel for where they see deficiencies or unknowns. Be sure to do this outside the audit report and response process. Invite them to review policies and standards, and enlist them to ensure that future controls have strong record-keeping and validation.

The special nature of the QSA

Although security professionals often think of the QSA as an auditor, there are important differences. As defined by the Payment Card Industry Data Security Standard (PCI DSS), a QSA is a specialist who assists a body subject to PCI DSS in being compliant with the standard's requirements, and who can provide an acceptable assessment of whether the organization has been successful in establishing and maintaining compliance.

PCI DSS is different from the gray and ambiguous nature of other compliance objectives such as Sarbanes-Oxley; it is a mixture of principles and specifics, which can be frustrating for security professionals. In some areas, it supports strong measures for protecting cardholder data; in others, it seems surprisingly lax. For example, PCI recommends against Wired Equivalent Privacy (WEP), a known flawed protocol, but still allows it to be used until June 2010.

Don't miss need-to-know info!

Security pros can't afford to be the last to know. Sign up for email updates from SearchSecurity.com and you'll never be behind the curve!
The QSA is also likely to be a security specialist by trade, rather than an auditor. No auditor feels right about acting as a consultant and advisor, and then turning around and judging what they just recommended, yet QSAs are allowed to do so, and many do. QSAs may be associated with a firm that sells or implements products for PCI DSS compliance, and may be under pressure to promote their firms' products or services. Recognizing these issues will better prepare security leaders to deal with QSAs effectively and professionally.

Any firm large enough to have a dedicated security staff is likely to be what PCI defines as a Level 1, 2 or 3 merchant or service provider. The scale is loosely based on the company's number of annual credit card transactions, or the nature of the business. Regardless of the particular firm's classification, it's possible to make a great start on QSA relations in the same way as with any other auditor: by knowing what questions he or she will ask before they're asked.

Fortunately, by downloading the Security Audit Procedures from the PCI Security Standards Council website, you can review the framework that QSAs use to conduct onsite reviews and validate PCI compliance. Level 2, 3 and 4 merchants are required to perform self-assessments using the documents published on that website, whereas Level 1 merchants must have an assessment performed by a qualified third-party QSA. The full effect of this document is reserved for Level 1 merchants, but anybody that handles credit card information will benefit from basing their PCI compliance on a documented target such as this.

Finally, remember that PCI DSS compliance reaches far beyond encryption, storage or protecting transactions. If the information security team is tasked with all PCI compliance activities, it's important to be much more involved with business processes and record-keeping. Build a strong relationship with the CFO, controllers and operational managers, and you can present a single voice to the QSA -- everyone involved will be better for it.

About the author:
Tony Higgins, CISSP-ISSMP, CISA, CIPP, is a consultant specializing in information security, privacy, and compliance, who has recently worked in the resort, gaming, and financial sectors.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Compliance Counselor,   Security Audit, Compliance and Standards,   IT Security Audits,   Information Security Management,   Information Security Policies, Procedures and Guidelines,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Compliance Counselor
Identity lifecycle management for security and compliance
Interpreting 'risk' in the Massachusetts data protection law
FTC Red Flags Rules: How to create an identity theft prevention plan
Creating a HIPAA employee training program
Data protection tips for corporate compliance leaders
PCI DSS compliance requirements: Ensuring data integrity
Understanding PCI DSS compliance requirements for log management
Are 'strong authentication' methods strong enough for compliance?
Strategies for using technology to enable automated compliance
Common PCI questions: Web application firewalls or source code review?

IT Security Audits
Standards compliance does not equal sound information security risk management
Tony Spinelli: Prioritize Information Security over Compliance
How to prepare for a FERPA audit
MasterCard increases PCI compliance requirements for some merchants
How to select a set of network security audit guidelines
How to write a risk methodology that blends business, security needs
PCI compliance requirement 11: Testing
Using IAM tools to improve compliance
Forensic accounting success depends on information security support
HIPAA compliance: New regulations change the game

Information Security Policies, Procedures and Guidelines
Health Net breach failure of security policy, technology
How to protect distributed information flows
Essential guide: Pandemic planning for H1N1
Whitelists, SaaS modify traditional security, tackle flaws
Melissa Hathaway urges more cooperation, government attention to cybersecurity
Reuters: Obama ready to select cyber security czar
How a corporate Twitter policy can combat social network threats
Should enterprises be concerned with Twitter in the workplace?
Information security management hype: Debunking best practices
Data breach avoidance begins with security basics, panel says

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
defense in depth  (SearchSecurity.com)
non-disclosure agreement  (SearchSecurity.com)
security policy  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts