Posts Tagged ‘Vendor Management’

h1

Hardening Procedures

April 8, 2009

As an IT audit and penetration testing firm, one of the key areas we see as deficient in most organizations is system hardening, specifically pre-deployment hardening procedures. These procedures provide guidelines to securing computer systems prior to installation for official business use. It is sometimes difficult to determine why organizations may not have hardening procedures.  Read the rest of this entry ?

h1

Why are Operating Systems and other Software full of Security Holes?

January 22, 2009

It’s been a bit more than ten years now since the security industry began calling attention to buggy software development practices.  And despite the security industry’s best efforts, most software development companies continue to produce code with security flaws. Read the rest of this entry ?

h1

Are you “at the mercy of your service provider”?

January 2, 2009

We received an email today from a credit union examiner in the eastern United States.  We had the privilege of providing him a week of IT training earlier in the year through our relationship with NASCUS.  He wrote, “So many of these small to medium size shops are at the mercy of the service provider and therefore rely on them for everything… what kind of detail should a vendor provide to the credit union about IT controls?” Read the rest of this entry ?