Windows Security - Audit Risk
50 pts.
0
Q:
Windows Security - Audit Risk
I am performing internal audit on windows security monitoring process.  The client performs periodic review of windows domain administrators to detect if there were any unauthorized access.  For one of the review, we found out the individual was reviewing her own activity. My first thought is that this could be an SoD conflict.

I am trying to understand the audit risk with this process.  There is no financial systems in scope that sit on Windows OS except for ADP, which is managed by third party vendor.  Is there any financial audit risk with this?  If the domain admin did attempt to login to windows, would there be any impact to the financial systems or is this just security risk with windows only?  Appreciate any insights on this.  Thanks.  John.



Software/Hardware used:
Windows
ASKED: Nov 5 2009  7:33 PM GMT
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _
0
23905 pts.
0
A:
 RATE THIS ANSWER
0
Click to Vote:
  •   0
  •  0
  • AddThis Social Bookmark Button
If the ADP database lives on that server, there could a security risk. To avoid the risk the database files should be encrypted and access should be restricted by a separate set of login credentials.
Last Answered: Nov 7 2009  0:33 AM GMT by Mshen   23905 pts.
0
0
Discuss This Answer:
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _



0