Audit Checklist for Securing Remote Access Connections
------------------------------ ---
- Examine access control policy and procedures; security plan,
information system design documentation, or other relevant documents;
reviewing for (1) the list of authorized methods of remote access to
include both establishment of the remote connection and subsequent user
actions across that connection, and (2) the measures and their
configuration settings (where applicable) to be employed to authorize,
monitor, and control these implemented methods of remote access to the
information system.
- Examine documentation describing the current
configuration settings for an agreed-upon representative sample of the
mechanisms; reviewing for evidence that the mechanisms are configured.
- Examine an agreed-upon representative sample of records associated
with the remote access monitoring activities; reviewing for evidence
that the remote access monitoring activities are employed as intended
- Examine the remote access control activities; observing for further
evidence that the remote access control activities are employed as
intended.
Objectives
- Determine if the information system
employs automated mechanisms to facilitate the monitoring and control of
remote access methods.
Checklist
- Examine security plan,
information system design documentation, or other relevant documents;
reviewing for the automated mechanisms and their configuration settings
to be employed to facilitate the monitoring and control of remote access
methods.
- Examine documentation describing the current
configuration settings for an agreed-upon representative sample of the
mechanisms; reviewing for evidence that the mechanisms are configured.
- Test an agreed-upon representative sample of automated mechanisms;
conducting generalized testing for evidence that the mechanisms operate
as intended.
Audit Checklist for Securing Remote Access Connections
------------------------------- Examine access control policy and procedures; security plan, information system design documentation, or other relevant documents; reviewing for (1) the list of authorized methods of remote access to include both establishment of the remote connection and subsequent user actions across that connection, and (2) the measures and their configuration settings (where applicable) to be employed to authorize, monitor, and control these implemented methods of remote access to the information system.
- Examine documentation describing the current configuration settings for an agreed-upon representative sample of the mechanisms; reviewing for evidence that the mechanisms are configured.
- Examine an agreed-upon representative sample of records associated with the remote access monitoring activities; reviewing for evidence that the remote access monitoring activities are employed as intended
- Examine the remote access control activities; observing for further evidence that the remote access control activities are employed as intended.
Objectives
- Determine if the information system employs automated mechanisms to facilitate the monitoring and control of remote access methods.
Checklist
- Examine security plan, information system design documentation, or other relevant documents; reviewing for the automated mechanisms and their configuration settings to be employed to facilitate the monitoring and control of remote access methods.
- Examine documentation describing the current configuration settings for an agreed-upon representative sample of the mechanisms; reviewing for evidence that the mechanisms are configured.
- Test an agreed-upon representative sample of automated mechanisms; conducting generalized testing for evidence that the mechanisms operate as intended.

Audit Checklist: How Tight Is Your IT Security?
------------------------------ -----
Based on my experiences, I will guide you a special checklist of areas
to be given special attention during an IT security audit.
Management has to provide a clear policy document and strong leadership
in an attempt to reduce liability, downtime, loss of business and
embarrassment that may arise as a result of an IT related security
issue. As part of this policy document, there has to be a clear IT
security audit checklist.
Enforcing a Sound Policy
Protocols and Services – Computer hardware, network components and
software applications usually come from the manufacturers with a set of
installed services, protocols and configurations that is intended to
meet the needs of a wide-range of users. Unfortunately, some of these
services, settings and protocols can make the system in question
unsecure and less efficient. Ensure that unused protocols and services
are disabled or uninstalled, and that the security settings don’t
conflict with the overall security policy of the organization.
Business Resumption and Disaster Recovery Plan – Just in case the worst
happens, an organization needs to have a plan to recover lost data and
bring mission critical resources back online as soon as possible. The
disaster recovery plan should also mitigate against any future loss of
resources or time due to natural disasters, accidents or a criminal act.
For your disaster recovery or business resumption plan to be effective,
it must include plans to have frequent system backups done and to store
a copy of those backups off-site. The recovery plan should also include
contact numbers for key personnel in case of an emergency, replacement
for IT and office resources, the identification of alternate facilities,
and detailed recovery procedures.
Anti-virus - No IT Security
Audit Checklist is complete without an accounting for an organization’s
vulnerability to computer viruses. All computers should be protected
with an up-to-date antivirus and anti-malware programs. If possible, the
software should be set to notify an administrator if a threat is found.
Network Security – Are all Internet access points documented,
authorized, and protected by firewalls, intrusion detection systems,
virtual private networks, and an incident responses system?
Remote Access Points - Ensure that all remote access facilities are known, encrypted, and duly authorized.
Passwords – Change all vendor-supplied, access codes and default
passwords for installed systems that have been changed or disabled.
Leaving default access codes on installed operating systems, database
management systems, network devices and applications is a major security
risk. Such passwords and access codes can be used to breach your
security measures if they are not changed.
See the complete Bright Hub Guide to Standards for Small-Business Network Security »
Also ensure that the users are using unique and strong passwords and
require that they change their passwords at reasonable time intervals.
Security Updates and Software Patches – Do all systems have the latest
software patches installed to protect them from know vulnerabilities?
Frequent Audits – Despite the best efforts of IT professionals,
breaches may remain on a network or may be created as software becomes
outdated and users interact with IT systems. Audits must be done
regularly to find these vulnerabilities.
Confidentiality
Agreements – Have employees, contracted workers, business partners, and
suppliers been asked to sign confidentiality agreements before
proprietary and/or sensitive information is disclosed to them? Doing so
ensures that there is a legal recourse should a breach occur and damages
are realized. Ideally, they should acknowledge, in writing, that they
understand the terms they are signing to.
Physical Security -
Are the servers, network equipment and other sensitive IT resources
physically secured? Physically securing your equipment will ensure that
unauthorized persons will find it difficult to breach your security
measures. Secure your sensitive and mission critical equipment by
locking them away or otherwise restrict who has access to them by using
access cards, security guards, and locked doors.
Audit Checklist: How Tight Is Your IT Security?
------------------------------
Based on my experiences, I will guide you a special checklist of areas to be given special attention during an IT security audit.
Management has to provide a clear policy document and strong leadership in an attempt to reduce liability, downtime, loss of business and embarrassment that may arise as a result of an IT related security issue. As part of this policy document, there has to be a clear IT security audit checklist.
Enforcing a Sound Policy
Protocols and Services – Computer hardware, network components and software applications usually come from the manufacturers with a set of installed services, protocols and configurations that is intended to meet the needs of a wide-range of users. Unfortunately, some of these services, settings and protocols can make the system in question unsecure and less efficient. Ensure that unused protocols and services are disabled or uninstalled, and that the security settings don’t conflict with the overall security policy of the organization.
Business Resumption and Disaster Recovery Plan – Just in case the worst happens, an organization needs to have a plan to recover lost data and bring mission critical resources back online as soon as possible. The disaster recovery plan should also mitigate against any future loss of resources or time due to natural disasters, accidents or a criminal act. For your disaster recovery or business resumption plan to be effective, it must include plans to have frequent system backups done and to store a copy of those backups off-site. The recovery plan should also include contact numbers for key personnel in case of an emergency, replacement for IT and office resources, the identification of alternate facilities, and detailed recovery procedures.
Anti-virus - No IT Security Audit Checklist is complete without an accounting for an organization’s vulnerability to computer viruses. All computers should be protected with an up-to-date antivirus and anti-malware programs. If possible, the software should be set to notify an administrator if a threat is found.
Network Security – Are all Internet access points documented, authorized, and protected by firewalls, intrusion detection systems, virtual private networks, and an incident responses system?
Remote Access Points - Ensure that all remote access facilities are known, encrypted, and duly authorized.
Passwords – Change all vendor-supplied, access codes and default passwords for installed systems that have been changed or disabled. Leaving default access codes on installed operating systems, database management systems, network devices and applications is a major security risk. Such passwords and access codes can be used to breach your security measures if they are not changed.
See the complete Bright Hub Guide to Standards for Small-Business Network Security »
Also ensure that the users are using unique and strong passwords and require that they change their passwords at reasonable time intervals.
Security Updates and Software Patches – Do all systems have the latest software patches installed to protect them from know vulnerabilities?
Frequent Audits – Despite the best efforts of IT professionals, breaches may remain on a network or may be created as software becomes outdated and users interact with IT systems. Audits must be done regularly to find these vulnerabilities.
Confidentiality Agreements – Have employees, contracted workers, business partners, and suppliers been asked to sign confidentiality agreements before proprietary and/or sensitive information is disclosed to them? Doing so ensures that there is a legal recourse should a breach occur and damages are realized. Ideally, they should acknowledge, in writing, that they understand the terms they are signing to.
Physical Security - Are the servers, network equipment and other sensitive IT resources physically secured? Physically securing your equipment will ensure that unauthorized persons will find it difficult to breach your security measures. Secure your sensitive and mission critical equipment by locking them away or otherwise restrict who has access to them by using access cards, security guards, and locked doors.

Understand the insider attack and how to prevent it (countermeasure)?
------------------------------ ----
Many companies focus all of their security efforts on keeping out
hackers and other network intruders. But from my perspective, the threat
posed by an insider attack is actually greater than that of external
hackers and viruses.
If you consider the full attack path of an
external hacker, the first step is to gain internal access.
Organizations expend an extraordinary amount of resources on protecting
their perimeter specifically to counter this threat. For the malicious
insiders, though, these countermeasures don’t apply, since these people
are already on the inside and they enjoy a certain implicit trust.
We rarely encounter internal networks that have the same monitoring and
controls as the organization’s perimeter. What you need to do to create
an effective security policy is understand your attack surface.
1. Ask the right security questions.
Measures such as security awareness, phishing preventions, etc., don’t
have a meaningful impact in cases where the attack is coming from the
inside, because the deliberate insider is going to go out of his way to
avoid detection. So ask yourself: Is your network flat, or is it
logically and physically segregated? If flat, the insider can use his
access to propagate from machine to machine, from HR to finance to
executives’ laptops. Are your users’ local administrators on their own
machines? If so, it’s easy for them to obtain similar access on other
machines, particularly if passwords are shared.
2. Know what your data is worth and who wants it.
In the case of both internal and external attacks, make sure you know
where all your sensitive information is located, and monitor or block
unauthorized access or movement. Not all data should be treated equally.
Classify your information so you can design and implement the proper
controls for different types of data.
Also, know what your
assets are and what value they have in the marketplace, including the
black market. Try to identify who might be after those assets and
monitor forums, chat rooms and social networking sites for suspicious
activity about your organization. Have an established escalation
procedure for dealing with incidents, and run drills to make sure that
procedure is operating effectively.
3. Set preventive measures for insider attacks.
There are simple methods to prevent employees from copying sensitive
data to a USB stick or an MP3 player. Endpoints should be configured to
disable all removable devices. Mobile devices -- like laptops,
smartphones or PDAs -- should have full disk encryption, and your
company should have the ability to erase them remotely if they are lost
or stolen.
4. Recognize suspicious behavior.
It’s a mistake
to rely just on preventive measures. Instead, supplement them with
monitoring and auditing so attacks can be detected and truly stopped by
removing the attacker from the organization. Although it’s difficult to
prevent a malicious attack from a motivated insider, there are ways to
spot bad behavior before it becomes a big problem. Each employee has
logical patterns of information usage, and the organization should look
for abnormal usage and investigate when this occurs. For example, if an
employee looks at 50 customer accounts each day and then one day looks
at 100 or more, there is a potential issue that should be investigated.
You always need to understand if unusual behavior is warranted or
malicious.
5. Manage incident response.
Incident response
is a very tricky and precise job. Even a small mistake can lead to major
pieces of evidence being lost or some other evidence being tainted in a
way that makes it inadmissible in court. If your security team is not
trained and certified in incident response, you should have a
relationship with an organization that is and call them as soon as you
identify a problem. They’ll likely want to get on the ground
immediately.
6. Keep your IT workers happy.
The best
defense against internal attacks has more to do with human relations and
organizational effectiveness than with technology. In the simplest
terms, the best way to avoid insider attacks is to make sure employees
are satisfied. Every company should have a support system for those who
feel they’ve been wronged by the company, so issues can be addressed
before retaliation occurs.
Security is not just a technology
issue. No matter what the size of an organization is, everyone is part
of the security team. Each employee has the opportunity to improve or
erode your company’s security each day. Lead by example and make your
employees feel included in the efforts to protect the company and its
customers.
Understand the insider attack and how to prevent it (countermeasure)?
------------------------------
Many companies focus all of their security efforts on keeping out hackers and other network intruders. But from my perspective, the threat posed by an insider attack is actually greater than that of external hackers and viruses.
If you consider the full attack path of an external hacker, the first step is to gain internal access. Organizations expend an extraordinary amount of resources on protecting their perimeter specifically to counter this threat. For the malicious insiders, though, these countermeasures don’t apply, since these people are already on the inside and they enjoy a certain implicit trust.
We rarely encounter internal networks that have the same monitoring and controls as the organization’s perimeter. What you need to do to create an effective security policy is understand your attack surface.
1. Ask the right security questions.
Measures such as security awareness, phishing preventions, etc., don’t have a meaningful impact in cases where the attack is coming from the inside, because the deliberate insider is going to go out of his way to avoid detection. So ask yourself: Is your network flat, or is it logically and physically segregated? If flat, the insider can use his access to propagate from machine to machine, from HR to finance to executives’ laptops. Are your users’ local administrators on their own machines? If so, it’s easy for them to obtain similar access on other machines, particularly if passwords are shared.
2. Know what your data is worth and who wants it.
In the case of both internal and external attacks, make sure you know where all your sensitive information is located, and monitor or block unauthorized access or movement. Not all data should be treated equally. Classify your information so you can design and implement the proper controls for different types of data.
Also, know what your assets are and what value they have in the marketplace, including the black market. Try to identify who might be after those assets and monitor forums, chat rooms and social networking sites for suspicious activity about your organization. Have an established escalation procedure for dealing with incidents, and run drills to make sure that procedure is operating effectively.
3. Set preventive measures for insider attacks.
There are simple methods to prevent employees from copying sensitive data to a USB stick or an MP3 player. Endpoints should be configured to disable all removable devices. Mobile devices -- like laptops, smartphones or PDAs -- should have full disk encryption, and your company should have the ability to erase them remotely if they are lost or stolen.
4. Recognize suspicious behavior.
It’s a mistake to rely just on preventive measures. Instead, supplement them with monitoring and auditing so attacks can be detected and truly stopped by removing the attacker from the organization. Although it’s difficult to prevent a malicious attack from a motivated insider, there are ways to spot bad behavior before it becomes a big problem. Each employee has logical patterns of information usage, and the organization should look for abnormal usage and investigate when this occurs. For example, if an employee looks at 50 customer accounts each day and then one day looks at 100 or more, there is a potential issue that should be investigated. You always need to understand if unusual behavior is warranted or malicious.
5. Manage incident response.
Incident response is a very tricky and precise job. Even a small mistake can lead to major pieces of evidence being lost or some other evidence being tainted in a way that makes it inadmissible in court. If your security team is not trained and certified in incident response, you should have a relationship with an organization that is and call them as soon as you identify a problem. They’ll likely want to get on the ground immediately.
6. Keep your IT workers happy.
The best defense against internal attacks has more to do with human relations and organizational effectiveness than with technology. In the simplest terms, the best way to avoid insider attacks is to make sure employees are satisfied. Every company should have a support system for those who feel they’ve been wronged by the company, so issues can be addressed before retaliation occurs.
Security is not just a technology issue. No matter what the size of an organization is, everyone is part of the security team. Each employee has the opportunity to improve or erode your company’s security each day. Lead by example and make your employees feel included in the efforts to protect the company and its customers.

Understand the computer forensic science
------------------------------ ---
Computer forensic science is a branch of digital forensic science
pertaining to legal evidence found in computers and digital storage
media. The goal of computer forensics is to examine digital media in a
forensically sound manner with the aim of identifying, preserving,
recovering, analyzing and presenting facts and opinions about the
information.
Although it is
most often associated with the investigation of a wide variety of
computer crime, computer forensics may also be used in civil
proceedings. The discipline involves similar techniques and principles
to data recovery, but with additional guidelines and practices designed
to create a legal audit trail.
Evidence from computer forensics
investigations is usually subjected to the same guidelines and
practices of other digital evidence. It has been used in a number of
high-profile cases and is becoming widely accepted as reliable within US
and European court systems.
Otherwise, this skills is very
limited and rarely knowledge of advancement of technology and cyber
crime in our country. I hope one day we will have this course to
spreading out this knowledge to all cambodian technology guys who
attempt to be cyber security forensic investigator.
Understand the computer forensic science
------------------------------Computer forensic science is a branch of digital forensic science pertaining to legal evidence found in computers and digital storage media. The goal of computer forensics is to examine digital media in a forensically sound manner with the aim of identifying, preserving, recovering, analyzing and presenting facts and opinions about the information.
Although it is most often associated with the investigation of a wide variety of computer crime, computer forensics may also be used in civil proceedings. The discipline involves similar techniques and principles to data recovery, but with additional guidelines and practices designed to create a legal audit trail.
Evidence from computer forensics investigations is usually subjected to the same guidelines and practices of other digital evidence. It has been used in a number of high-profile cases and is becoming widely accepted as reliable within US and European court systems.
Otherwise, this skills is very limited and rarely knowledge of advancement of technology and cyber crime in our country. I hope one day we will have this course to spreading out this knowledge to all cambodian technology guys who attempt to be cyber security forensic investigator.

Understand malicious software countermeasures
------------------------------ ---
Attacks using malicious software are growing in number and
sophistication. Antivirus, Anti-Spyware and other protection products
continue to play a game of catch-up. New, increasingly complex
variations are continuously being introduced and can sometimes spread
widely before protection software companies deliver the latest detection
strings and solutions.
Dealerships need to develop a malicious
software strategy that clearly outlines the objectives and procedures
for malicious software control and recovery. Introducing security
measures can involve some risk and these practices should be done under
the advice of qualified dealer network management.
Security
Awareness- user awareness is one of the most powerful countermeasures in
virus control. Data should only be accepted from trusted sources. Users
should be warned not to open suspicious email or visit 'hostile'
websites. Furthermore, users should not be free to introduce unchecked
media on to systems.
Patch Management- patch management is the
process of updating your servers or PCs with the latest security patches
and service packs. Writers of viruses, spyware and other malicious
software exploit existing flaws in software loaded on a PC to spread and
do damage. Software companies will issue patches to fix flaws once they
have been discovered. Using automatic updates to detect available
patches for security vulnerabilities is vital to maintaining proper
system functioning. However, there are times when installing a patch or
update may actually interfere with current processes. Therefore, avoid
automatic installation options. Use the following process to manage
automatic updates:
Detect - use automatic updates to scan your systems for missing security patches and trigger the patch management process.
Assess - determine the severity of the issue(s) addressed by the patch
and any other factors that may influence your decision, balancing the
severity of the issue and mitigating factors to determine if the
vulnerabilities are a threat to your current environment.
Acquire - if the vulnerability is not addressed by the security measures already in place, download the patch for testing.
Test - install the patch on a test system to verify the ramifications of the update against your production configuration.
Deploy - deploy the patch to production computers. Make sure your
applications are not affected. Employ your rollback or backup restore
plan if needed.
Maintain - subscribe to notifications that alert you to vulnerabilities as they are reported.
Anti-virus scanners - these products scan files and email and instant
messaging programs for signature patterns that match known malicious
software. Since new viruses are continually emerging, these products can
only be effective if they are regularly updated with the latest virus
signatures. See your product manual for instructions on how to activate
this. Anti-virus scanners can be positioned on gateways to the network
and/or on network hosts. Anti-virus scanners need to be frequently
updated to be effective. Therefore, regularity and method of update are
criteria that need to be considered when selecting anti-virus products.
Audit information - audit logs, including firewall logs, may detect
abnormal activity. Examples are Trojans attempting to send data from a
site, or malicious programs attempting to write or read to unauthorized
areas.
System hardening - careful implementation of system
access controls, and the policy of running applications with least
privilege, can minimize the damage caused by malicious software. This
needs to be coupled with tight configuration management procedures.
Active Content Blocking - blocks unwanted internet traffic and protects
the network from malicious content on websites and spam emails. It also
helps ensure business resources are being used for business purposed.
There are four things you should look for in an internet blocking or
filtering system:
Automatic Updates
Centralized Administration
Category Based Products
Reporting Capabilities
Firewalls - firewalls can restrict the ability of some remote control
programs to execute if they rely on a port that is generally blocked. A
firewall can be either PC or server based. Firewalls are most effective
at the Internet's point of entry. However, not a large degree of
reliance can be placed on firewalls for malicious software control
unless a gateway incorporates an active content filter.
Understand malicious software countermeasures
------------------------------
Attacks using malicious software are growing in number and sophistication. Antivirus, Anti-Spyware and other protection products continue to play a game of catch-up. New, increasingly complex variations are continuously being introduced and can sometimes spread widely before protection software companies deliver the latest detection strings and solutions.
Dealerships need to develop a malicious software strategy that clearly outlines the objectives and procedures for malicious software control and recovery. Introducing security measures can involve some risk and these practices should be done under the advice of qualified dealer network management.
Security Awareness- user awareness is one of the most powerful countermeasures in virus control. Data should only be accepted from trusted sources. Users should be warned not to open suspicious email or visit 'hostile' websites. Furthermore, users should not be free to introduce unchecked media on to systems.
Patch Management- patch management is the process of updating your servers or PCs with the latest security patches and service packs. Writers of viruses, spyware and other malicious software exploit existing flaws in software loaded on a PC to spread and do damage. Software companies will issue patches to fix flaws once they have been discovered. Using automatic updates to detect available patches for security vulnerabilities is vital to maintaining proper system functioning. However, there are times when installing a patch or update may actually interfere with current processes. Therefore, avoid automatic installation options. Use the following process to manage automatic updates:
Detect - use automatic updates to scan your systems for missing security patches and trigger the patch management process.
Assess - determine the severity of the issue(s) addressed by the patch and any other factors that may influence your decision, balancing the severity of the issue and mitigating factors to determine if the vulnerabilities are a threat to your current environment.
Acquire - if the vulnerability is not addressed by the security measures already in place, download the patch for testing.
Test - install the patch on a test system to verify the ramifications of the update against your production configuration.
Deploy - deploy the patch to production computers. Make sure your applications are not affected. Employ your rollback or backup restore plan if needed.
Maintain - subscribe to notifications that alert you to vulnerabilities as they are reported.
Anti-virus scanners - these products scan files and email and instant messaging programs for signature patterns that match known malicious software. Since new viruses are continually emerging, these products can only be effective if they are regularly updated with the latest virus signatures. See your product manual for instructions on how to activate this. Anti-virus scanners can be positioned on gateways to the network and/or on network hosts. Anti-virus scanners need to be frequently updated to be effective. Therefore, regularity and method of update are criteria that need to be considered when selecting anti-virus products.
Audit information - audit logs, including firewall logs, may detect abnormal activity. Examples are Trojans attempting to send data from a site, or malicious programs attempting to write or read to unauthorized areas.
System hardening - careful implementation of system access controls, and the policy of running applications with least privilege, can minimize the damage caused by malicious software. This needs to be coupled with tight configuration management procedures.
Active Content Blocking - blocks unwanted internet traffic and protects the network from malicious content on websites and spam emails. It also helps ensure business resources are being used for business purposed. There are four things you should look for in an internet blocking or filtering system:
Automatic Updates
Centralized Administration
Category Based Products
Reporting Capabilities
Firewalls - firewalls can restrict the ability of some remote control programs to execute if they rely on a port that is generally blocked. A firewall can be either PC or server based. Firewalls are most effective at the Internet's point of entry. However, not a large degree of reliance can be placed on firewalls for malicious software control unless a gateway incorporates an active content filter.
