Omegaswift
Cyber Security

What a Security Audit Actually Checks

Audit is one word for four different jobs. Knowing which one you are buying is the difference between a useful report and an expensive PDF.

The Omegaswift engineering teamSecurity engineering9 min read

Four Different Jobs, One Word

A vulnerability scan is a tool. It looks at what it can reach, compares it against a list of known weaknesses, and prints what it finds. It is cheap, it should run every week rather than once a year, and on its own it says nothing about whether anybody could actually get in.

A penetration test is a person trying to reach an agreed goal under agreed rules. It answers a narrower question than most buyers expect. Not whether you are safe, but whether this tester, in this window, inside this scope, could get to this one thing.

A gap assessment measures what you do against a written standard and reports the difference. A compliance audit checks your evidence against a standard so that somebody can sign a certificate at the end. Only the last of those produces a certificate. The other three produce work.

Most people asking for an audit want the third and buy the first. The report arrives, it is enormous, nobody can act on it, and the whole idea gets a bad name in your company for two years.

Scope Is the Whole Argument

Scope is settled before any technical work starts, and it decides what the report is worth. The systems that get looked at are rarely all the systems you have.

Name these explicitly, because they are left out by default. Cloud accounts a department set up on somebody's card. The company you bought last year that still runs its own logins. Machines on the factory floor. Other people's systems holding your data. Test environments with a copy of real customer records in them. And the phones with your email on them.

Ask for the scope as a list of systems rather than as a sentence. A phrase like the office network can be read four ways by four people, and it will be, on the day a finding turns out to sit just outside it.

What a Thorough Check Looks At

Logins first, and hardest. Who has administrator rights and why. Whether those accounts are separate from the ones the same people use for email. Where two step sign in is switched on, and where somebody quietly turned it off for one system. What happens to an account on the day somebody leaves. And the service accounts running with permanent privilege and a password that has not changed since the system was installed.

Then the edge and the machines. What faces the internet on purpose, and what faces it by accident. Whether remote access goes through something that logs and checks. How fast updates get installed. Whether the security software on the laptops is actually reporting, or merely present.

Then the things that only matter after something has happened. Whether logs exist. Whether they are kept long enough to investigate something you find out about late. Whether anybody reads them. And whether the backups can be reached with the same password an attacker would take first.

Then the parts that are not technology at all. How new staff get accounts and how leavers lose them. Who is allowed to approve a change. What your suppliers can reach. And how somebody reports an email that looks wrong without feeling stupid. A tidy network with no way to report anything is one convincing email away from a bad month.

Severity, and the Long List Trap

A scanner grades a finding on the properties of the weakness. It does not know what the affected system does, whether anyone outside can reach it, or whether it holds anything worth taking. A critical rating on a test machine and a medium rating on the server holding your customer records are in the wrong order.

Ask for severity to be set with your business in mind, and for the report to say what the tester believes somebody could actually achieve and in what order. Three medium findings that chain together into full control of everything are the most important paragraph in the document. No tool will present it that way, because no tool knows.

Be just as suspicious of a very short report. An assessment that finds almost nothing usually had a scope that guaranteed it.

The Fix List Is the Real Deliverable

A finding with no owner, no estimate and no date is a sentence, not a plan. What you are paying for is an ordered list. Fix this week. Fix this quarter. This one needs a project and a budget. This one we are choosing to live with for now, and here is the reason.

The order matters more than the length. Some fixes remove a whole class of problem and shorten everything underneath them. Taking permanent administrator rights away from daily accounts changes the severity of a large part of the rest of the list.

Agree the retest in the same contract. A finding is closed when somebody has checked that it is closed, not when a ticket says so.

How Often, and What Should Pull One Forward

Scanning that runs continuously, an independent look once a year, and a penetration test whenever something significant changes is a reasonable rhythm for most businesses. The annual one exists to catch drift, because every environment decays quietly and always in the direction of whatever was convenient at the time.

Some events should pull an assessment forward whatever the calendar says. Buying another company. Moving onto a new platform. A big change in who can get in from outside. The departure of the person who knew how everything was wired together. And any incident, however small, that nobody can fully explain.

Written by

The Omegaswift engineering team

Security engineering at Omegaswift. Filed under Cyber Security.

Ask us about this

Ready to talk about your IT?

We are happy to answer any questions you have and help you work out which of our services fit your needs.