Skip to main content

Questions tagged [audit]

For questions about the assessment of software, hardware, systems, people, processes, procedures, projects, etc, that are somehow related to the security of an organization or product. Often these are related to a certification the organization or product holds, or looking for tools or processes for performing an audit.

0 votes
0 answers
13 views

I tried to search the web on existing projects, but after failed attempts, I decided to code something on my own way, one approach, open to comments and improvements: #!/usr/bin/env python3 import ...
Gilles Quénot's user avatar
0 votes
0 answers
15 views

I discovered ExtAnalysis, tried to run it in a Docker container, but this seems that this project is abandoned. There's too many errors. Some issues are opened since 2023 in the repository. So my ...
Gilles Quénot's user avatar
0 votes
1 answer
70 views

It's common for companies seeking certification in advanced security environments to require all employees to work on company issued or managed equipment. It's also common to not allow data access to ...
Wesley's user avatar
  • 113
10 votes
1 answer
1k views

We have our first ISO27001 audit coming up soon. We did a practice audit with our external ISO advisor and it was just a paper exercise, asking if we have different policies and then reading through ...
Fearg_005's user avatar
  • 103
0 votes
1 answer
112 views

Canonical, the publishers of Ubuntu, create their own set of security patches for packages in Ububtu's "universe" repository of community-maintained software. They make these patches ...
interfect's user avatar
  • 313
1 vote
0 answers
161 views

My company is developing an open-source platform that would be hosted on may different servers, deployed in the cloud by many people, that run the "LAMP" stack or something similar. My goal ...
Gregory Magarshak's user avatar
6 votes
2 answers
208 views

I read a LinkedIn article by Chris Hall (Post 1, Post 2), who states that Certification Auditors cannot and should not raise nonconformity against the controls and should only raise nonconformity ...
Sinclair Hirst's user avatar
2 votes
0 answers
120 views

Background: There are a lot of self-hosted web applications these days, and often, more than one for the same purpose. In my case I am looking for a replacement for GitHub or other big tech/cloud git ...
The Floating Brain's user avatar
0 votes
2 answers
336 views

From personal experience many mobile apps that I've tested don't actively detect and discourage (with a warning) or even block the app from running on/in: a rooted/jailbroken Android/iOS device ...
Bob Ortiz's user avatar
  • 7,715
2 votes
0 answers
55 views

I am looking for ways to value add to existing Office 365 Security & Compliance center which is available by default. Adding HIPPA compliant check but I don't wanna pay for the templates available ...
user598526's user avatar
1 vote
0 answers
142 views

I am working on a data processing task in an enterprise environment with Python3 installed on a client-side Windows Jump server. I need to download data regularly from a third-party provider, and it ...
gale44's user avatar
  • 11
0 votes
1 answer
199 views

Could you please suggest if I need to do anything else to ensure that my server is secure against the most common attacks? Currently it seems fine to me, but I would highly appreciate if someone with ...
dooshnila's user avatar
1 vote
1 answer
196 views

I would like to know if there is a way to run an app to exhaustion in terms of all possible outcomes that it can provide. What do I mean by that: Let's assume that someone has an (Apache) HTTP Server. ...
und3rd06012's user avatar
0 votes
1 answer
199 views

We want to be 27001 certified and our company is based on one core application that is hosted in our cloud infrastructure but provided by a vendor. Is there a situation where an auditor needs access ...
Ritchie1962's user avatar
-1 votes
2 answers
338 views

Suppose you need a laptop repair, so you bring it to A big box store where you have some sort of coverage (who will have the computer for 2-3 weeks) A small chain of repair shops a small independent ...
SurferTaco's user avatar

15 30 50 per page
1
2 3 4 5
31