IT Audit Proposal (Reserve for Professor Mitch)

profilegao1279
677_Final_Example1.pdf

Running Head: ZIFFCORP AUDIT PROPOSAL 1

ZiffCorp Audit IT Security Audit Proposal

Brian A. McDougall

Central Washington University

Author Note:

Final Paper – IT 677 – Summer 2018

ZIFFCORP AUDIT PROPOSAL 2

Table of Contents

Title Page .......................................................................................................................................................................... 1

Table of Contents .......................................................................................................................................................... 2

Audit Proposal ................................................................................................................................................................ 3

Entity-Level Controls .................................................................................................................................................. 4

Data Center ...................................................................................................................................................................... 8

Database ......................................................................................................................................................................... 11

Web Server .................................................................................................................................................................... 13

Cloud ................................................................................................................................................................................ 14

Disaster Preparedness Plan .................................................................................................................................. 15

References ..................................................................................................................................................................... 16

ZIFFCORP AUDIT PROPOSAL 3

Audit Proposal July 26, 2018

Artie Ziff, CEO

ZiffCorp

1066 3rd St

Springfield, VA 22150

Dear Mr. Ziff:

Thank you for the opportunity to present my proposal to perform an informal audit of

certain critical IT security policies and controls at ZiffCorp. Because of recent changes in

privacy regulations, GDPR in particular, I feel it expedient to review certain controls in

preparation for a formal audit that will verify ZiffCorp’s compliance to GDPR across the

organization. This audit is essential to maintaining quality operations and further help in

mitigating organizational risk, which can easily end up in dollars lost (Collins, 2017).

Let me stress that this will be an informal audit to be performed in order to assess our

security footing in certain areas of the company’s IT infrastructure. Our auditors will

review security controls and issue recommendations for closing any gaps they may find in

the process. ZiffCorp’s information security executives will then present the board with

proposals to adjust current controls or implement additional controls that will aid in

helping prepare ZiffCorp for a GDPR compliance audit. As always, the board will have full

control over making decisions as to accepting, mitigating, or transferring any risks related

to the audit team’s recommendations.

Failure to comply with GDPR results in two levels of fines. The first is up to €10 million or 2% of the company’s global profits for the previous financial year, whichever is higher. The

second is up to €20 million or 4% of the company’s global profits for the previous year,

whichever is higher (GDPR Group Ltd., 2018). As you can see, failure to comply could result

in serious financial damage. The scope of this audit will cover controls at the entity level,

data center, database, web server, cloud infrastructure and vendors, and the IT disaster

recovery preparedness plan. This audit will employ one audit team and is expected to take

2 -3 weeks.

Thank you,

Brian McDougall

Chief Information Security Officer (CISO)

ZIFFCORP AUDIT PROPOSAL 4

ZiffCorp Audit IT Security Audit Proposal

The following is an outline describing the areas and controls to be covered in this proposed

informal audit. The purpose for entity-level controls will be summarized in order to

express their importance in identifying and mitigating risk. The audit will include entity-

level controls, data center controls, database controls, web server controls, cloud

infrastructure controls, and the disaster preparedness plan.

Entity-Level Controls

Entity-level controls are pervasive across the whole company. For this reason,

they’ll be the first area covered by the audit. Once these controls have been assessed, they

will not need to be considered when auditing individual systems or types of information.

This portion of the audit covers the areas that should be centralized within the company

because they provide for the core principles of IT governance (Davis, Schiller, & Wheeler,

2011).

A poorly defined IT organizational structure can lead to confusion of responsibilities

and ineffective performance of support functions. This can also lead to disagreement over

who has decision-making authority as lines of authority are not clearly established.

Therefore, we will review the overall IT organizational structure, paying particular

attention how effectively lines of authority are defined, including proper separation of

duties (Davis et al., 2011).

Without a strategy regarding where it plans to go, the IT department will be in a

reactive mode dealing with day-to-day issues and crises. This does not provide for an

effective long-term outlook. Upcoming business trends and environmental changes must be

properly planned for, so the IT department can react effectively. Therefore, we will review

ZIFFCORP AUDIT PROPOSAL 5

the strategic planning process to ensure that it properly aligns with stated business

strategies. An assessment of processes for monitoring progress against the strategic plan

will be included. In addition, we will determine whether an effective technology and

application strategy and roadmap exists and revue processes for long-range technical

planning (Davis et al., 2011).

The purpose of the IT department is to support the business and its day-to-day

operations. Minimum performance standards must be established and measured in order

to determine whether the IT department’s is adequately providing these services. We will

review performance indicators and measurements for IT, any processes and metrics that

are in place for measuring performance of day-to-day activities as well as tracking

performance against service-level agreements (SLAs), budgets, and operational

requirements (Davis et al., 2011).

The company must have a structured process for approving and prioritizing new IT

projects in order to efficiently deploy IT resources. Without such a process, it is more likely

that the project will fail to meet its key goals and milestones because management and key

stakeholders will be unable to effectively review the project’s progress. We will review the

IT department’s process for approving and prioritizing new projects, ensuring that only

approved projects may commence. Standards for governing the execution of IT projects

will also be assessed, along with processes and standards for ensuring the quality of

products developed or acquired by the IT department (Davis et al., 2011).

Without effective IT security policies, there will be no set processes in place, or

baseline of expectations, identifying how employees should deal with security-related

issues. Lenient policies don’t provide adequate protections and strict policies are often

ZIFFCORP AUDIT PROPOSAL 6

ignored or place unnecessary costs and overhead on the company. In addition, these

policies must be effectively communicated to employees in order for them to be followed

properly. Therefore, we will ensure that existing IT security policies provide adequate

controls for the security of ZiffCorp’s systems and information. We will also review

processes for communicating these policies to employees and for monitoring and enforcing

compliance. Processes for reporting problems by end users will also be assessed for

effectiveness and availability (Davis et al., 2011).

Risk assessment processes are critical to the IT department’s ability to stay aware of

risks that will hinder its ability to achieve its business objectives. We will evaluate the IT

department’s risk-assessment processes as well as its ability to effectively make decisions

regarding the acceptance or mitigation of those risks (Davis et al., 2011).

We will review hiring and termination procedures for clarity and to ensure that they

are comprehensive. The majority of these will be HR policies and procedures for

background checks, drug screening, clear and comprehensive job descriptions, access

revocation procedures, etc. We will also review IT department processes for ensuring that

IT employees possess adequate skills and knowledge to perform their duties, including

performance feedback procedures and ongoing training for updating skills. Also to be

reviewed are any processes and policies concerning the termination of access upon an

employee leaving the organization or taking a new role, including third-party personnel

(Davis et al., 2011).

In order to properly and effectively protect company data, IT must have a

framework in place for determining, and ensuring, necessary protections, data

classification levels and data life cycles. We will evaluate any policies and processes for

ZIFFCORP AUDIT PROPOSAL 7

assigning ownership and classifying data, as well as protections in accordance to its

classification, and the definition of its lifecycle (Davis et al., 2011).

It goes without saying that ZiffCorp could face stiff penalties and fines, a damaged

reputation, lawsuits, and possible terminal damage, if it is found to be in violation of

applicable laws and regulations. We will review processes for monitoring and ensuring

compliance to legal and regulatory requirements (Davis et al., 2011).

If third-party vendors and IT support/service providers are not managed

appropriately, they cannot be held accountable for providing poor service or quality. If

their access to ZiffCorp’s information assets are not properly governed and communicated,

company information assets risk unnecessary exposure and misuse. Therefore, we will

assess processes for evaluating and selecting vendors, and third-party services. These

processes should clearly define and monitory their performance. We will also review and

evaluate processes for controlling logical access to third-party personnel (Davis et al.,

2011).

The improper or illegal use of software can bring penalties, fines, and lawsuits

against ZiffCorp. This includes software that is downloaded and installed off the Internet by

employees, as well as legitimately purchased software that is used in excess of proper use

agreements. We will assess processes for ensuring compliance with applicable software

licenses and for ensuring that only properly licensed software is installed on company

computers (Davis et al., 2011).

Remote access is a valuable tool for providing access to ZiffCorp’s information

resources. Without proper controls in place, it can also be a vulnerability in the company

network and a risk to its information assets. We will evaluate remote access controls

ZIFFCORP AUDIT PROPOSAL 8

including proper use and configuration of VPNs, dial-up connections (if any), dedicated

external connections, and authentication/user verification, as well as the removal of access

when users leave the organization or change roles. This includes third-party access (Davis

et al., 2011).

Concerning ZiffCorp’s information systems themselves, we will review policies and

procedures for the procurement and movement of hardware, system configuration change

controls and mechanisms, as well as capacity monitoring and planning. Also included will

be a review of policies and processes concerning the proper transportation, storage, reuse,

and disposal of physical storage media (Davis et al., 2011).

Data Center

The majority of the focus during the data center audit will be on physical

controls. Most of the logical controls utilized within the data center are audited with

operating systems, servers, networking equipment and protocols, databases, web sites,

security implementations, etc. The following are the controls to be examined, as well as

associated maintenance logs. The majority of them will be fairly self-explanatory as to their

importance in controlling risk. Along with the controls themselves, we will review any

related policies and procedures for the use, testing, monitoring, and life-cycle of the

controls and physical equipment.

External Risk Factors and Neighborhood

We will review whether the facility has adequate exterior lighting and fences to

prevent and deter crime and loitering. Exterior signage should not advertise to passers-by

that the facility or room contains a data center. Are their any hazards in close proximity

such as danger of flooding from damaged pipes, chemicals, vehicle accidents or car bombs,

ZIFFCORP AUDIT PROPOSAL 9

similar damage from neighboring businesses, etc.? We will also review the facility’s

proximity to emergency services, and environmental hazards such as floods, earthquakes,

tornadoes, local crime rates, etc. (Davis et al., 2011).

Physical Access Controls

We will assess the effectiveness of any implemented physical barriers such as

exterior doors and walls, authentication mechanisms, physical access control procedures,

and security guard routes, procedures, and logs. We will also ensure that the data center is

adequately protected by burglar alarms and surveillance systems, and that access is

properly restricted. Finally, we will review whether systems and equipment that is

essential to operations is located within the secure data center (Davis et al., 2011).

Environmental Controls

We will ensure that the HVAC system is maintaining proper, consistent

temperatures within the data center and that water alarms are configured correctly and

functioning (Davis et al., 2011).

Power and Electricity

We will inspect redundant power feeds to the data center, the ground-to-earth

connection, UPSs for power conditioning and battery backup power sufficient to data

center needs, and that emergency power-off switches are protected to adequately prevent

accidental shutdown. We will also inspect backup generators and determine whether they

are adequate to data center needs, regularly inspected and tested, and that sufficient fuel is

stocked. Relatedly, we will review all procedures and processes for the use of this

equipment in emergency situations, as well as employee knowledge of their individual

roles and responsibilities when these measures are required (Davis et al., 2011).

ZIFFCORP AUDIT PROPOSAL 10

Fire Suppression

We will review existing building features to ensure that construction materials are

fire-resistant. We will assess whether data center personnel are trained in the proper

handling, storage, and disposal of hazmat materials, as well as their training concerning

emergency procedures related to such materials. Fire extinguishers should be strategically

placed throughout the data and regularly inspected/maintained. We will also inspect the

condition of fire suppression systems and verify that fire alarms are adequately protecting

the data center from the risk of fire (Davis et al., 2011).

Data Center Operations

We will review alarm monitoring equipment, reports, and procedures, verifying that

they are being continually monitored. We will verify the adequacy of network, OS, and

application monitoring measures, verify that personnel roles and responsibilities are

clearly defined and understood, that proper segregation of duties is in place, and that

emergency response procedures adequately address anticipated threats. We will also

verify that facility-based systems and equipment are being regularly maintained and that

personnel are properly trained to perform their job duties. Additionally, capacity planning

and asset management processes should be in place and in line with potential

organizational needs. We will also assess whether electronic media is being stored and

disposed of according to entity-level policy (Davis et al., 2011).

System Resilience

We will verify that hardware redundancy is sufficient and that duplicate systems are

used in cases of high system availability requirements (Davis et al., 2011).

ZIFFCORP AUDIT PROPOSAL 11

Backup and Restore

We will review backup procedures and capacity are adequate, that backup media

can be promptly retrieved from their offsite storage location when needed and verify that

systems can actually be restored from the backups (Davis et al., 2011).

Disaster Recovery Planning

A disaster recovery plan (DRP) is critical for ensuring that the data center can get up

and going again while eliminating downtime and streamlining processes and procedures

for recovering from a catastrophic damage or outage. We will verify that the data center

has a DRP, that employees are aware of their roles in implementing it, and that it is updated

and tested regularly. We will also verify that vendor agreements and parts inventories are

accurate and current, and that emergency plans adequately address all realistic potential

disaster scenarios (Davis et al., 2011).

Database

General

Any host operating systems will be audited separately as part of a server audit. We

will verify that the running database version is currently supported and meets corporate

policy requirements. We will also verify that patch management policies and procedures

are adequate and that all approved patches are installed. We will also review current

standards for standard builds and whether baseline builds are adequately secured via

security settings (Davis et al., 2011).

Operating System

We will ensure that OS access, directory permissions, and registry keys are properly

restricted (Davis et al., 2011).

ZIFFCORP AUDIT PROPOSAL 12

Account Permission Management

We will assess standing procedures for creating and removing, or disabling, user

accounts are implemented properly and promptly. Additionally, we will review password

strength and management features, such as the existence of default authentication

credentials and accounts, as well as password complexity and password management

controls to ensure that they meet ZiffCorp company policy (Davis et al., 2011).

Database Privileges

We will review database privileges by ensuring that permissions are appropriate for

the required level of authorization, not granted implicitly or incorrectly, and are granted to

individuals rather than groups or roles. We will also check that SQL is executed in stored

procedures, that row-level access to table data is properly implemented, and that PUBLIC

permissions have been revoked where they aren’t needed (Davis et al., 2011).

Data Encryption

We will verify that network encryption is properly applied to databases both on

data in transit and at rest (Davis et al., 2011).

Monitoring and Management

We will review the use of database auditing and activity monitoring, capacity

management, and evaluate performance management and monitoring to verify that it can

support present and future anticipated business requirements (Davis et al., 2011).

Web Server

Host Operating System

As with databases, any host operating systems will be audited separately as part of a

server audit.

ZIFFCORP AUDIT PROPOSAL 13

Web Servers

As with the databases, we will verify that the running database version is currently

supported and meets corporate policy requirements. We will also verify that patch

management policies and procedures are adequate and that all approved patches are

installed. We will also review current standards for standard builds and whether baseline

builds are adequately secured via security settings. We will also assure that no unnecessary

services, modules, objects, or APIs are open or in use, and that access is only allowed via

appropriate ports and protocols (Davis et al., 2011).

In addition, we will verify that running services and modules are operating under

the least privileged accounts. Accounts allowing access to the web server should utilize

appropriate password complexity. We will also verify that files and directories have

appropriate controls applied to them, that logging is enabled and secured, that script

extensions are mapped appropriately, and that server certificates are valid (Davis et al.,

2011).

Web Applications

We will review whether the web app is protected against injection attacks, cross-

site-scripting, URL filtering, as well as broken authentication and session management

vulnerabilities. We will verify that proper controls are in place, and enforced, on object

reference and authorization and maintaining a secure configuration. Encryption should be

adequately applied to storage and network traffic. We will also evaluate error handling and

input validation controls and ensure that the web app properly redirects and forwards to

verify that only valid URLs are accessible (Davis et al., 2011).

ZIFFCORP AUDIT PROPOSAL 14

Cloud

Preliminary

An actual audit of the cloud vendor and its datacenter is typically not typically a

realistic task. They host data from a lot of clients and must keep it protected to their

standards. For this reason, it is common practice to request independent assurance of the

effectiveness of their internal controls from a reputable third party, such as an SAS 70 Type

2 report. While reviewing these certifications, we will identify any gaps between them and

our own security control objectives (Davis et al., 2011).

Vendor Selection and Contracts

We will review vendor contracts to verify that they identify all deliverables,

requirements, and responsibilities required by ZiffCorp upon engaging with the vendor. We

will also evaluate vendor selection processes (Davis et al., 2011).

Data Security

We will review data segregation from other client data, the use of encryption as

applied to data in storage and in transit, controls on vendor employee access to ZiffCorp

systems, and processes for controlling non-employee logical access to our internal network

and systems. We will verify that proper protections are in place over ZiffCorp data stored at

vendor locations, and evaluate their controls for attack prevention, detection, and reaction.

We will also look at how identity management is handled, that offsite data is handled in

accordance to internal retention and destruction policies, and physical security controls at

the could vendor’s facilities (Davis et al., 2011).

Operations

We will assess processes for monitoring the quality of outsourced operations, SLAs

ZIFFCORP AUDIT PROPOSAL 15

and contractual requirements, DRP process at vendor locations, ensuring quality of vendor

IT staff, and termination of outsourcing relationships. We will also review governance

processes over the engagement of new cloud services and vendors (Davis et al., 2011).

Legal and Regulatory Compliance

We will evaluate ZiffCorp’s right and ability to obtain information from vendors in

the case of investigations and eDiscovery requests. We will review security breach

notification requirements, and how compliance to privacy laws and other regulations, as

well as software licenses is ensured (Davis et al., 2011).

Disaster Preparedness Plan

A disaster recovery plan (DRP) is critical for ensuring that ZiffCorp systems can get

up and going again while eliminating downtime and streamlining processes and

procedures for recovering from a catastrophic damage or outage. We will verify that a DRP

is in place, that employees are aware of their roles in implementing it, and that it is updated

and tested regularly. We will also verify that vendor agreements and parts inventories are

accurate and current, and that emergency plans adequately address all realistic potential

disaster scenarios (Davis et al., 2011).

We will verify that the company DRP includes adequate emergency operations

plans, adequate testing and verification of DRP controls, and that contacts, roles and

procedures are clearly defined and well-known by pertinent personnel. We will also verify

the existence and availability of departmental and sub-unit DRPs (Davis et al., 2011).

ZIFFCORP AUDIT PROPOSAL 16

References

Collins, J. (2017, September 26). How to write a proposal for an audit. Retrieved July 26,

2018, from https://bizfluent.com/how-8059787-write-proposal-audit.html

Davis, C., Schiller, M., & Wheeler, K. (2011). IT auditing: Using controls to protect

information assets (2nd ed.). New York, NY: McGraw-Hill.

GDPR Group Ltd. (2018). GDPR data breach penalties and fines. Retrieved July 26, 2018,

from https://www.gdpr.associates/data-breach-penalties/