An auditor should be aware of various security testing tools and techniques to determine the security environment of the organization. To evaluate the security risks and controls, an auditor should be well versed in auditing techniques.
General security controls
An IS auditor can adopt the following testing techniques for security controls:
Terminal controls
The following are some of the important aspects with respect to terminal controls:
- An auditor should obtain access cards and keys and attempt to enter the restricted area. This will ensure that access controls are effective and operational.
- An auditor should determine and verify whether the terminal list has been updated and reconciled with addresses and locations. The IS auditor should select a few terminals and try to locate them in the network diagram.
- An auditor should verify whether any unsuccessful attempts to access the terminals are monitored at regular intervals and whether appropriate...