IT Audit Proposal (Reserve for Professor Mitch)
Running Head: ZIFFCORP AUDIT PROPOSAL 1
ZiffCorp Audit IT Security Audit Proposal
Brian A. McDougall
Central Washington University
Author Note:
Final Paper – IT 677 – Summer 2018
ZIFFCORP AUDIT PROPOSAL 2
Table of Contents
Title Page .......................................................................................................................................................................... 1
Table of Contents .......................................................................................................................................................... 2
Audit Proposal ................................................................................................................................................................ 3
Entity-Level Controls .................................................................................................................................................. 4
Data Center ...................................................................................................................................................................... 8
Database ......................................................................................................................................................................... 11
Web Server .................................................................................................................................................................... 13
Cloud ................................................................................................................................................................................ 14
Disaster Preparedness Plan .................................................................................................................................. 15
References ..................................................................................................................................................................... 16
ZIFFCORP AUDIT PROPOSAL 3
Audit Proposal July 26, 2018
Artie Ziff, CEO
ZiffCorp
1066 3rd St
Springfield, VA 22150
Dear Mr. Ziff:
Thank you for the opportunity to present my proposal to perform an informal audit of
certain critical IT security policies and controls at ZiffCorp. Because of recent changes in
privacy regulations, GDPR in particular, I feel it expedient to review certain controls in
preparation for a formal audit that will verify ZiffCorp’s compliance to GDPR across the
organization. This audit is essential to maintaining quality operations and further help in
mitigating organizational risk, which can easily end up in dollars lost (Collins, 2017).
Let me stress that this will be an informal audit to be performed in order to assess our
security footing in certain areas of the company’s IT infrastructure. Our auditors will
review security controls and issue recommendations for closing any gaps they may find in
the process. ZiffCorp’s information security executives will then present the board with
proposals to adjust current controls or implement additional controls that will aid in
helping prepare ZiffCorp for a GDPR compliance audit. As always, the board will have full
control over making decisions as to accepting, mitigating, or transferring any risks related
to the audit team’s recommendations.
Failure to comply with GDPR results in two levels of fines. The first is up to €10 million or 2% of the company’s global profits for the previous financial year, whichever is higher. The
second is up to €20 million or 4% of the company’s global profits for the previous year,
whichever is higher (GDPR Group Ltd., 2018). As you can see, failure to comply could result
in serious financial damage. The scope of this audit will cover controls at the entity level,
data center, database, web server, cloud infrastructure and vendors, and the IT disaster
recovery preparedness plan. This audit will employ one audit team and is expected to take
2 -3 weeks.
Thank you,
Brian McDougall
Chief Information Security Officer (CISO)
ZIFFCORP AUDIT PROPOSAL 4
ZiffCorp Audit IT Security Audit Proposal
The following is an outline describing the areas and controls to be covered in this proposed
informal audit. The purpose for entity-level controls will be summarized in order to
express their importance in identifying and mitigating risk. The audit will include entity-
level controls, data center controls, database controls, web server controls, cloud
infrastructure controls, and the disaster preparedness plan.
Entity-Level Controls
Entity-level controls are pervasive across the whole company. For this reason,
they’ll be the first area covered by the audit. Once these controls have been assessed, they
will not need to be considered when auditing individual systems or types of information.
This portion of the audit covers the areas that should be centralized within the company
because they provide for the core principles of IT governance (Davis, Schiller, & Wheeler,
2011).
A poorly defined IT organizational structure can lead to confusion of responsibilities
and ineffective performance of support functions. This can also lead to disagreement over
who has decision-making authority as lines of authority are not clearly established.
Therefore, we will review the overall IT organizational structure, paying particular
attention how effectively lines of authority are defined, including proper separation of
duties (Davis et al., 2011).
Without a strategy regarding where it plans to go, the IT department will be in a
reactive mode dealing with day-to-day issues and crises. This does not provide for an
effective long-term outlook. Upcoming business trends and environmental changes must be
properly planned for, so the IT department can react effectively. Therefore, we will review
ZIFFCORP AUDIT PROPOSAL 5
the strategic planning process to ensure that it properly aligns with stated business
strategies. An assessment of processes for monitoring progress against the strategic plan
will be included. In addition, we will determine whether an effective technology and
application strategy and roadmap exists and revue processes for long-range technical
planning (Davis et al., 2011).
The purpose of the IT department is to support the business and its day-to-day
operations. Minimum performance standards must be established and measured in order
to determine whether the IT department’s is adequately providing these services. We will
review performance indicators and measurements for IT, any processes and metrics that
are in place for measuring performance of day-to-day activities as well as tracking
performance against service-level agreements (SLAs), budgets, and operational
requirements (Davis et al., 2011).
The company must have a structured process for approving and prioritizing new IT
projects in order to efficiently deploy IT resources. Without such a process, it is more likely
that the project will fail to meet its key goals and milestones because management and key
stakeholders will be unable to effectively review the project’s progress. We will review the
IT department’s process for approving and prioritizing new projects, ensuring that only
approved projects may commence. Standards for governing the execution of IT projects
will also be assessed, along with processes and standards for ensuring the quality of
products developed or acquired by the IT department (Davis et al., 2011).
Without effective IT security policies, there will be no set processes in place, or
baseline of expectations, identifying how employees should deal with security-related
issues. Lenient policies don’t provide adequate protections and strict policies are often
ZIFFCORP AUDIT PROPOSAL 6
ignored or place unnecessary costs and overhead on the company. In addition, these
policies must be effectively communicated to employees in order for them to be followed
properly. Therefore, we will ensure that existing IT security policies provide adequate
controls for the security of ZiffCorp’s systems and information. We will also review
processes for communicating these policies to employees and for monitoring and enforcing
compliance. Processes for reporting problems by end users will also be assessed for
effectiveness and availability (Davis et al., 2011).
Risk assessment processes are critical to the IT department’s ability to stay aware of
risks that will hinder its ability to achieve its business objectives. We will evaluate the IT
department’s risk-assessment processes as well as its ability to effectively make decisions
regarding the acceptance or mitigation of those risks (Davis et al., 2011).
We will review hiring and termination procedures for clarity and to ensure that they
are comprehensive. The majority of these will be HR policies and procedures for
background checks, drug screening, clear and comprehensive job descriptions, access
revocation procedures, etc. We will also review IT department processes for ensuring that
IT employees possess adequate skills and knowledge to perform their duties, including
performance feedback procedures and ongoing training for updating skills. Also to be
reviewed are any processes and policies concerning the termination of access upon an
employee leaving the organization or taking a new role, including third-party personnel
(Davis et al., 2011).
In order to properly and effectively protect company data, IT must have a
framework in place for determining, and ensuring, necessary protections, data
classification levels and data life cycles. We will evaluate any policies and processes for
ZIFFCORP AUDIT PROPOSAL 7
assigning ownership and classifying data, as well as protections in accordance to its
classification, and the definition of its lifecycle (Davis et al., 2011).
It goes without saying that ZiffCorp could face stiff penalties and fines, a damaged
reputation, lawsuits, and possible terminal damage, if it is found to be in violation of
applicable laws and regulations. We will review processes for monitoring and ensuring
compliance to legal and regulatory requirements (Davis et al., 2011).
If third-party vendors and IT support/service providers are not managed
appropriately, they cannot be held accountable for providing poor service or quality. If
their access to ZiffCorp’s information assets are not properly governed and communicated,
company information assets risk unnecessary exposure and misuse. Therefore, we will
assess processes for evaluating and selecting vendors, and third-party services. These
processes should clearly define and monitory their performance. We will also review and
evaluate processes for controlling logical access to third-party personnel (Davis et al.,
2011).
The improper or illegal use of software can bring penalties, fines, and lawsuits
against ZiffCorp. This includes software that is downloaded and installed off the Internet by
employees, as well as legitimately purchased software that is used in excess of proper use
agreements. We will assess processes for ensuring compliance with applicable software
licenses and for ensuring that only properly licensed software is installed on company
computers (Davis et al., 2011).
Remote access is a valuable tool for providing access to ZiffCorp’s information
resources. Without proper controls in place, it can also be a vulnerability in the company
network and a risk to its information assets. We will evaluate remote access controls
ZIFFCORP AUDIT PROPOSAL 8
including proper use and configuration of VPNs, dial-up connections (if any), dedicated
external connections, and authentication/user verification, as well as the removal of access
when users leave the organization or change roles. This includes third-party access (Davis
et al., 2011).
Concerning ZiffCorp’s information systems themselves, we will review policies and
procedures for the procurement and movement of hardware, system configuration change
controls and mechanisms, as well as capacity monitoring and planning. Also included will
be a review of policies and processes concerning the proper transportation, storage, reuse,
and disposal of physical storage media (Davis et al., 2011).
Data Center
The majority of the focus during the data center audit will be on physical
controls. Most of the logical controls utilized within the data center are audited with
operating systems, servers, networking equipment and protocols, databases, web sites,
security implementations, etc. The following are the controls to be examined, as well as
associated maintenance logs. The majority of them will be fairly self-explanatory as to their
importance in controlling risk. Along with the controls themselves, we will review any
related policies and procedures for the use, testing, monitoring, and life-cycle of the
controls and physical equipment.
External Risk Factors and Neighborhood
We will review whether the facility has adequate exterior lighting and fences to
prevent and deter crime and loitering. Exterior signage should not advertise to passers-by
that the facility or room contains a data center. Are their any hazards in close proximity
such as danger of flooding from damaged pipes, chemicals, vehicle accidents or car bombs,
ZIFFCORP AUDIT PROPOSAL 9
similar damage from neighboring businesses, etc.? We will also review the facility’s
proximity to emergency services, and environmental hazards such as floods, earthquakes,
tornadoes, local crime rates, etc. (Davis et al., 2011).
Physical Access Controls
We will assess the effectiveness of any implemented physical barriers such as
exterior doors and walls, authentication mechanisms, physical access control procedures,
and security guard routes, procedures, and logs. We will also ensure that the data center is
adequately protected by burglar alarms and surveillance systems, and that access is
properly restricted. Finally, we will review whether systems and equipment that is
essential to operations is located within the secure data center (Davis et al., 2011).
Environmental Controls
We will ensure that the HVAC system is maintaining proper, consistent
temperatures within the data center and that water alarms are configured correctly and
functioning (Davis et al., 2011).
Power and Electricity
We will inspect redundant power feeds to the data center, the ground-to-earth
connection, UPSs for power conditioning and battery backup power sufficient to data
center needs, and that emergency power-off switches are protected to adequately prevent
accidental shutdown. We will also inspect backup generators and determine whether they
are adequate to data center needs, regularly inspected and tested, and that sufficient fuel is
stocked. Relatedly, we will review all procedures and processes for the use of this
equipment in emergency situations, as well as employee knowledge of their individual
roles and responsibilities when these measures are required (Davis et al., 2011).
ZIFFCORP AUDIT PROPOSAL 10
Fire Suppression
We will review existing building features to ensure that construction materials are
fire-resistant. We will assess whether data center personnel are trained in the proper
handling, storage, and disposal of hazmat materials, as well as their training concerning
emergency procedures related to such materials. Fire extinguishers should be strategically
placed throughout the data and regularly inspected/maintained. We will also inspect the
condition of fire suppression systems and verify that fire alarms are adequately protecting
the data center from the risk of fire (Davis et al., 2011).
Data Center Operations
We will review alarm monitoring equipment, reports, and procedures, verifying that
they are being continually monitored. We will verify the adequacy of network, OS, and
application monitoring measures, verify that personnel roles and responsibilities are
clearly defined and understood, that proper segregation of duties is in place, and that
emergency response procedures adequately address anticipated threats. We will also
verify that facility-based systems and equipment are being regularly maintained and that
personnel are properly trained to perform their job duties. Additionally, capacity planning
and asset management processes should be in place and in line with potential
organizational needs. We will also assess whether electronic media is being stored and
disposed of according to entity-level policy (Davis et al., 2011).
System Resilience
We will verify that hardware redundancy is sufficient and that duplicate systems are
used in cases of high system availability requirements (Davis et al., 2011).
ZIFFCORP AUDIT PROPOSAL 11
Backup and Restore
We will review backup procedures and capacity are adequate, that backup media
can be promptly retrieved from their offsite storage location when needed and verify that
systems can actually be restored from the backups (Davis et al., 2011).
Disaster Recovery Planning
A disaster recovery plan (DRP) is critical for ensuring that the data center can get up
and going again while eliminating downtime and streamlining processes and procedures
for recovering from a catastrophic damage or outage. We will verify that the data center
has a DRP, that employees are aware of their roles in implementing it, and that it is updated
and tested regularly. We will also verify that vendor agreements and parts inventories are
accurate and current, and that emergency plans adequately address all realistic potential
disaster scenarios (Davis et al., 2011).
Database
General
Any host operating systems will be audited separately as part of a server audit. We
will verify that the running database version is currently supported and meets corporate
policy requirements. We will also verify that patch management policies and procedures
are adequate and that all approved patches are installed. We will also review current
standards for standard builds and whether baseline builds are adequately secured via
security settings (Davis et al., 2011).
Operating System
We will ensure that OS access, directory permissions, and registry keys are properly
restricted (Davis et al., 2011).
ZIFFCORP AUDIT PROPOSAL 12
Account Permission Management
We will assess standing procedures for creating and removing, or disabling, user
accounts are implemented properly and promptly. Additionally, we will review password
strength and management features, such as the existence of default authentication
credentials and accounts, as well as password complexity and password management
controls to ensure that they meet ZiffCorp company policy (Davis et al., 2011).
Database Privileges
We will review database privileges by ensuring that permissions are appropriate for
the required level of authorization, not granted implicitly or incorrectly, and are granted to
individuals rather than groups or roles. We will also check that SQL is executed in stored
procedures, that row-level access to table data is properly implemented, and that PUBLIC
permissions have been revoked where they aren’t needed (Davis et al., 2011).
Data Encryption
We will verify that network encryption is properly applied to databases both on
data in transit and at rest (Davis et al., 2011).
Monitoring and Management
We will review the use of database auditing and activity monitoring, capacity
management, and evaluate performance management and monitoring to verify that it can
support present and future anticipated business requirements (Davis et al., 2011).
Web Server
Host Operating System
As with databases, any host operating systems will be audited separately as part of a
server audit.
ZIFFCORP AUDIT PROPOSAL 13
Web Servers
As with the databases, we will verify that the running database version is currently
supported and meets corporate policy requirements. We will also verify that patch
management policies and procedures are adequate and that all approved patches are
installed. We will also review current standards for standard builds and whether baseline
builds are adequately secured via security settings. We will also assure that no unnecessary
services, modules, objects, or APIs are open or in use, and that access is only allowed via
appropriate ports and protocols (Davis et al., 2011).
In addition, we will verify that running services and modules are operating under
the least privileged accounts. Accounts allowing access to the web server should utilize
appropriate password complexity. We will also verify that files and directories have
appropriate controls applied to them, that logging is enabled and secured, that script
extensions are mapped appropriately, and that server certificates are valid (Davis et al.,
2011).
Web Applications
We will review whether the web app is protected against injection attacks, cross-
site-scripting, URL filtering, as well as broken authentication and session management
vulnerabilities. We will verify that proper controls are in place, and enforced, on object
reference and authorization and maintaining a secure configuration. Encryption should be
adequately applied to storage and network traffic. We will also evaluate error handling and
input validation controls and ensure that the web app properly redirects and forwards to
verify that only valid URLs are accessible (Davis et al., 2011).
ZIFFCORP AUDIT PROPOSAL 14
Cloud
Preliminary
An actual audit of the cloud vendor and its datacenter is typically not typically a
realistic task. They host data from a lot of clients and must keep it protected to their
standards. For this reason, it is common practice to request independent assurance of the
effectiveness of their internal controls from a reputable third party, such as an SAS 70 Type
2 report. While reviewing these certifications, we will identify any gaps between them and
our own security control objectives (Davis et al., 2011).
Vendor Selection and Contracts
We will review vendor contracts to verify that they identify all deliverables,
requirements, and responsibilities required by ZiffCorp upon engaging with the vendor. We
will also evaluate vendor selection processes (Davis et al., 2011).
Data Security
We will review data segregation from other client data, the use of encryption as
applied to data in storage and in transit, controls on vendor employee access to ZiffCorp
systems, and processes for controlling non-employee logical access to our internal network
and systems. We will verify that proper protections are in place over ZiffCorp data stored at
vendor locations, and evaluate their controls for attack prevention, detection, and reaction.
We will also look at how identity management is handled, that offsite data is handled in
accordance to internal retention and destruction policies, and physical security controls at
the could vendor’s facilities (Davis et al., 2011).
Operations
We will assess processes for monitoring the quality of outsourced operations, SLAs
ZIFFCORP AUDIT PROPOSAL 15
and contractual requirements, DRP process at vendor locations, ensuring quality of vendor
IT staff, and termination of outsourcing relationships. We will also review governance
processes over the engagement of new cloud services and vendors (Davis et al., 2011).
Legal and Regulatory Compliance
We will evaluate ZiffCorp’s right and ability to obtain information from vendors in
the case of investigations and eDiscovery requests. We will review security breach
notification requirements, and how compliance to privacy laws and other regulations, as
well as software licenses is ensured (Davis et al., 2011).
Disaster Preparedness Plan
A disaster recovery plan (DRP) is critical for ensuring that ZiffCorp systems can get
up and going again while eliminating downtime and streamlining processes and
procedures for recovering from a catastrophic damage or outage. We will verify that a DRP
is in place, that employees are aware of their roles in implementing it, and that it is updated
and tested regularly. We will also verify that vendor agreements and parts inventories are
accurate and current, and that emergency plans adequately address all realistic potential
disaster scenarios (Davis et al., 2011).
We will verify that the company DRP includes adequate emergency operations
plans, adequate testing and verification of DRP controls, and that contacts, roles and
procedures are clearly defined and well-known by pertinent personnel. We will also verify
the existence and availability of departmental and sub-unit DRPs (Davis et al., 2011).
ZIFFCORP AUDIT PROPOSAL 16
References
Collins, J. (2017, September 26). How to write a proposal for an audit. Retrieved July 26,
2018, from https://bizfluent.com/how-8059787-write-proposal-audit.html
Davis, C., Schiller, M., & Wheeler, K. (2011). IT auditing: Using controls to protect
information assets (2nd ed.). New York, NY: McGraw-Hill.
GDPR Group Ltd. (2018). GDPR data breach penalties and fines. Retrieved July 26, 2018,
from https://www.gdpr.associates/data-breach-penalties/