I would like to have a look at the standard list of questions that an auditor might ask when undertaking an SAS 70 audit……
Access control, ACL, Administrative privileges, Antivirus, Antivirus software, Application security, Auditing, Authentication, Biometrics, Cisco ASA, Cisco PIX, Current threats, Digital certificates, Encryption, Endpoint security, Firewalls, Forensics, Hacking, Identity & Access Management, Incident response, Information risk management, Intrusion management, ISA Server, McAfee, Password, Patch management, patching, PEN testing, Platform Security, Risk management, Secure Coding, Security in 2010, Security management, Security products, Security Program Management, Security tokens, SFTP, Single sign-on, SonicWALL, Spyware, SSL, SSL/TLS, Symantec, Trojans, User Permissions, Viruses, vulnerability management, Web security, Windows Security, worms >>VIEW ALL TAGS
