New SANS Audit Course (407) Live

The rumors are true, there is a new SANS audit class on the SANS courseware bookshelf. The course is Audit 407 – Foundations of Information Systems Audit. It’s a prequel…

Comments Off on New SANS Audit Course (407) Live

Script for Network Adapter Configuration Baselines

So in this series of blog articles so far we have identified a number of different baseline scripts written in PowerShell. We hope that auditors and others will be able…

Comments Off on Script for Network Adapter Configuration Baselines

Script for Network Share Baselines

Today we’re going to continue blogging about scripts that we can use to create system baselines. (For a primer on why you might want to consider performing a system baseline…

Comments Off on Script for Network Share Baselines

Script for Locally Installed Software Baselines

Today we’re going to continue blogging about scripts that we can use to create system baselines. (For a primer on why you might want to consider performing a system baseline…

Comments Off on Script for Locally Installed Software Baselines

Script for Local User and Group Baselines

In keeping with my New Year’s resolutions, I want to continue posting information on how an auditor might take advantage of baselines when performing an Information System (IS) audit. Certainly…

Comments Off on Script for Local User and Group Baselines

Examples of System Baselines

Ok, it sounds like we should have one more point of clarification. In our last blog post we posted about a process to follow for creating and maintaining system baselines.…

Comments Off on Examples of System Baselines

More Baselining Ideas – The Baselining Process

So I’ve had some questions about exactly what I mean by baselining and what types of things an auditor should be baselining when they’re examining a system. So let me…

Comments Off on More Baselining Ideas – The Baselining Process