Auditors and Company Policy

| | Comments (2) | TrackBacks (0)

Its always nice when your own auditors follow company policy. We have an external auditor in for the next 6 week in order to obtain FISMA certification. At the kickoff meeting, we told the auditors that they were not allowed to put their computers on our internal network, but they were more than welcome to use our guest wireless. This information was also on the account request form that they signed.

I had a feeling that they weren't going to follow our policy. We don't currently have a technical mechanism in place to enforce such a policy. I opened our DHCP management console and sure enough 5 computers had a DHCP lease with a computername and domain giving away that their owner was this auditing firm.

So I was able to bust them on that, and prove to them that we do review the logs and record anomalies in servicedesk.

Categories

,

0 TrackBacks

Listed below are links to blogs that reference this entry: Auditors and Company Policy.

TrackBack URL for this entry: http://www.infosecblog.org/mt-tb20071121.pl/591

2 Comments

What I am interested in: these auditors willingly and knowingly violated your company's policy. Was any action taken against the auditors? At the very least, I would think there has to be some form of compensation.

Roger Author Profile Page said:

Thanks for commenting.

That is currently not determined. I'll probably keep that detail under wraps.

Just speculating, I doubt there is anything in the contract about that. All we can do is complain to their company and ask for compensation.

Leave a comment

Powered by Ajax Comments

About this Entry

This page contains a single entry by Roger published on September 15, 2007 1:07 PM.

Third Brigade product integrated into Trend Micro antivirus software was the previous entry in this blog.

Why good passwords? is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.

Add to Google
Please contact me by leaving a comment where appropriate. Otherwise, you can click here to reveal an email address for me.
Got Backups? Get Safe Online Remember Rick Rescorla Powered by Movable Type 4.2-en