Auditing storage systems for security and compliance
Before jumping into the storage system audit process, review Chapter 2, Audit Planning and Preparation. As with any audit, we want to ensure that we engage stakeholders, develop a good scoping plan, and identify all the storage architecture before beginning the audit.
Assessing physical security controls for on-premises storage
Physical security controls might be easy to overlook, considering most organizations leverage cloud storage. However, some organizations that maintain on-premises storage systems to prevent unauthorized access, theft, or damage to the hardware and data must maintain a high physical security stance. When auditing physical security controls, consider the following:
- Access controls: Assessing access controls is necessary to ensure that only authorized personnel can physically access the storage systems and the facilities housing them. Auditors should do the following:
- Verify that access to the storage...