TESTIMONIALS

โ€œReceived the latest edition of Professional Security Magazine, once again a very enjoyable magazine to read, interesting content keeps me reading from front to back. Keep up the good work on such an informative magazine.โ€

Graham Penn
ALL TESTIMONIALS
FIND A BUSINESS

Would you like your business to be added to this list?

ADD LISTING
FEATURED COMPANY
News Archive

Tick Box IT Audit

by Msecadm4921

Most organisations still view compliance as an annual or quarterly project; an exercise to perform the minimum requirements to pass the audit. The end-goal of each project is on ticking the box marked โ€œcomplianceโ€ rather than to improve security and ensure the safeguard of valuable corporate assetsโ€”including brand reputation, writes Rob Warmack, EMEA Director, Tripwire.

The result of this โ€œtick boxโ€ attitude is a massive increase in pre-audit effort, with staff distracted from key business facing initiatives to gather reports and respond to deficiencies. Once the tick is achieved, staff slide back to their original tasks, and the company slides straight back out of compliance, until the next time.

What is required is a continuous approach to security and compliance, supported by way of automating the detection of suspicious events and changes that may lead to data compromise and, when needed, the rapid response to these changes to bring the organisation back into a secure and compliant state.

With this continuous approach organisations can move away from the expensive, inefficient peaks of audit activity. A compliant state is attained and then sustained through the ability to proactively fix vulnerabilities caused by a failed patch or seemingly harmless administrative change or to quickly react and defend systems from a live attack.

The goal, therefore, should not be about merely achieving compliance; but creating a culture of continuous security. Compliance will then be achieved more easily and with less costs, and organisations can raise security up from the base of regulatory compliance to a standard that truly reflects todayโ€™s level of corporate threat.