Security
Audits
Security Audits are a comprehensive review of an organization's
security posture. Security audits can focus in on an application
or the entire enterprise. A security audit determines the
difference between stated security requirements and goals
and actual security in an organization. This is a very verbose
process designed to be definitive in scope.
Requirements for a security audit are a stated security policy
that can be audited. The audit will follow the following major
steps:
1. Discovery
2. Security policy review
3. Policy audit
4. Findings
5. Recommendations and remediation
© 2003 Hudson Business Networks
|