5.14/5.14.1 Testing Technique For Security Controls Flashcards
What can an auditor do to test confidentiality ?
He could attempt to guess password of sample of employees
Walk into staff offices to check whether password is not written on a paper or wtv
What can an auditor do to test encryption ?
View the password table and check if the password are encrypted
What an auditor can do to test access authorisation ?
Review a sample of access authorisation to determine if proper authority has been provided and if the authorisation was correctly granted
How an auditor can test for the disabling of inactive logon IDs ?
Obtain an extract of active logon IDs and match it with the list of current employees, ensure there are no discrepancies
How an auditor can test for password syntaxe ?
The auditor should attempt to create a password in a format that is invalid (too short, too long , repeat from previous password etc)
How an auditor can test the control over production environnement ?
Work with software analyst and operation manager to determine if access is on a need to know basis. Working with security admin to determine who can access the resource and to do what
How an auditor can test for the reporting of access violation ?
Auditor should attempt to access computer unauthorised transactions or data. The attempt should be unsuccessful and identified on security report. The auditor should also assess the effectiveness of security admin to response to access violation
What an auditor can do it is review access controls and password admin?
Ensure procedures are existing
Ensure password cannot be easily guess
Ensure password are periodically changed
Regular review of access capabilities