7: Auditing Vulnerabilities Management Flashcards
Alert management
The IS auditor should determine if the organization actively searches for or subscribes to security alert bulletins. The auditor should examine procedures and records to see if any alert bulletins result in responsive actions such as applied security patches or configuration changes.
Infrastructure penetration testing
The IS auditor should determine if the organization performs any penetration testing on its own network and system infrastructure.
Application penetration testing
The IS auditor should determine if the organization performs any application penetration testing on its software applications to identify vulnerabilities.
Patch management
The IS auditor should examine procedures and records to determine if the organization performs any patch management activities.
The auditor should determine if patches are tested on nonproduction environment systems to understand their impact.