<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Network Security Blog &#187; Security Audit</title>
	<atom:link href="http://networksecurity.farzadbanifatemi.com/category/security-audit/feed" rel="self" type="application/rss+xml" />
	<link>http://networksecurity.farzadbanifatemi.com</link>
	<description>A Blog by Farzad Banifatemi</description>
	<lastBuildDate>Mon, 19 Apr 2010 19:31:13 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>active directory security group question?</title>
		<link>http://networksecurity.farzadbanifatemi.com/security-audit/active-directory-security-group-question</link>
		<comments>http://networksecurity.farzadbanifatemi.com/security-audit/active-directory-security-group-question#comments</comments>
		<pubDate>Fri, 16 Apr 2010 12:27:20 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security Audit]]></category>

		<guid isPermaLink="false">http://networksecurity.farzadbanifatemi.com/security-audit/active-directory-security-group-question</guid>
		<description><![CDATA[Ive got to audit all of our security groups and find what folders they have access to without having to look at every folder to see what permissions are on them, is there any scripts or free software out there to do this, Ive had a look at dumpsec and thats it
no free stuff&#8230;for this [...]]]></description>
			<content:encoded><![CDATA[<p>Ive got to audit all of our security groups and find what folders they have access to without having to look at every folder to see what permissions are on them, is there any scripts or free software out there to do this, Ive had a look at dumpsec and thats it<br />
<br />no free stuff&#8230;for this kind of proffesional work</p>

<!-- start wp-tags-to-technorati 1.01 -->

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://networksecurity.farzadbanifatemi.com/security-audit/active-directory-security-group-question/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Bandolier Demonstration</title>
		<link>http://networksecurity.farzadbanifatemi.com/security-audit/bandolier-demonstration</link>
		<comments>http://networksecurity.farzadbanifatemi.com/security-audit/bandolier-demonstration#comments</comments>
		<pubDate>Mon, 12 Apr 2010 06:39:15 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security Audit]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[Bandolier]]></category>
		<category><![CDATA[configuration]]></category>
		<category><![CDATA[DCS]]></category>
		<category><![CDATA[DigitalBond]]></category>
		<category><![CDATA[Historian]]></category>
		<category><![CDATA[HMI]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[nessus]]></category>
		<category><![CDATA[Realtime]]></category>
		<category><![CDATA[SCADA]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Tenable]]></category>

		<guid isPermaLink="false">http://networksecurity.farzadbanifatemi.com/security-audit/bandolier-demonstration</guid>
		<description><![CDATA[This is a video introduction and demonstration of Digital Bond&#8217;s Bandolier security audit files for control system servers and workstations. The audit files work with the policy compliance plugins in Nessus.
Duration : 0:8:35
[youtube 3Q-2qvcWzTc]



Technorati Tags: audit, Bandolier, configuration, DCS, DigitalBond, Historian, HMI, infosec, nessus, Realtime, SCADA, security, Tenable


]]></description>
			<content:encoded><![CDATA[<p><img src="http://i.ytimg.com/vi/3Q-2qvcWzTc/2.jpg" align="left">This is a video introduction and demonstration of Digital Bond&#8217;s Bandolier security audit files for control system servers and workstations. The audit files work with the policy compliance plugins in Nessus.</p>
<p>Duration : <b>0:8:35</b></p>
<p><span id="more-997"></span><br />[youtube 3Q-2qvcWzTc]</p>

<!-- start wp-tags-to-technorati 1.01 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/audit' rel='tag' target='_blank'>audit</a>, <a class='technorati-link' href='http://technorati.com/tag/Bandolier' rel='tag' target='_blank'>Bandolier</a>, <a class='technorati-link' href='http://technorati.com/tag/configuration' rel='tag' target='_blank'>configuration</a>, <a class='technorati-link' href='http://technorati.com/tag/DCS' rel='tag' target='_blank'>DCS</a>, <a class='technorati-link' href='http://technorati.com/tag/DigitalBond' rel='tag' target='_blank'>DigitalBond</a>, <a class='technorati-link' href='http://technorati.com/tag/Historian' rel='tag' target='_blank'>Historian</a>, <a class='technorati-link' href='http://technorati.com/tag/HMI' rel='tag' target='_blank'>HMI</a>, <a class='technorati-link' href='http://technorati.com/tag/infosec' rel='tag' target='_blank'>infosec</a>, <a class='technorati-link' href='http://technorati.com/tag/nessus' rel='tag' target='_blank'>nessus</a>, <a class='technorati-link' href='http://technorati.com/tag/Realtime' rel='tag' target='_blank'>Realtime</a>, <a class='technorati-link' href='http://technorati.com/tag/SCADA' rel='tag' target='_blank'>SCADA</a>, <a class='technorati-link' href='http://technorati.com/tag/security' rel='tag' target='_blank'>security</a>, <a class='technorati-link' href='http://technorati.com/tag/Tenable' rel='tag' target='_blank'>Tenable</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://networksecurity.farzadbanifatemi.com/security-audit/bandolier-demonstration/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How can a company confirm its total number of employees without disclosing personal information?</title>
		<link>http://networksecurity.farzadbanifatemi.com/security-audit/how-can-a-company-confirm-its-total-number-of-employees-without-disclosing-personal-information</link>
		<comments>http://networksecurity.farzadbanifatemi.com/security-audit/how-can-a-company-confirm-its-total-number-of-employees-without-disclosing-personal-information#comments</comments>
		<pubDate>Sun, 11 Apr 2010 09:42:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security Audit]]></category>

		<guid isPermaLink="false">http://networksecurity.farzadbanifatemi.com/security-audit/how-can-a-company-confirm-its-total-number-of-employees-without-disclosing-personal-information</guid>
		<description><![CDATA[We&#8217;re ranking local companies by number of employees for an industry report. We need to make sure the responding companies are truthful. What&#8217;s an easy and reasonable way for them to document or prove the number of employees they employ without disclosing confidential information like names, social security numbers, salaries, etc. Is there an employee [...]]]></description>
			<content:encoded><![CDATA[<p>We&#8217;re ranking local companies by number of employees for an industry report. We need to make sure the responding companies are truthful. What&#8217;s an easy and reasonable way for them to document or prove the number of employees they employ without disclosing confidential information like names, social security numbers, salaries, etc. Is there an employee audit they must submit for health insurance, workers compensation or state unemployment purposes? We need a simple, acceptable and standard method of accounting for the number of employees. We don&#8217;t want anyone fudging or misleading/misrepresenting their company.<br />
Allow me to clarify. Submitting to this list is voluntary. </p>
<p>And getting listed is valueable. Companies can&#8217;t wait to appear on this list each year!</p>
<p>To that end, we can set the standard or requirements to participate. </p>
<p>Therefore, we can and should request/require any reasonable documentation. </p>
<p>What documentation would you suggest or recommend that we can request/require that is reasonable, standard and acceptable documentation of true employment within a corporation?<br />
<br />What ever reports they must generate are not for you.  Unless you have a court order, you have no right to this information.  You have no choice but to take their word for it.</p>

<!-- start wp-tags-to-technorati 1.01 -->

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://networksecurity.farzadbanifatemi.com/security-audit/how-can-a-company-confirm-its-total-number-of-employees-without-disclosing-personal-information/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>what is auditing when it comes to web security?</title>
		<link>http://networksecurity.farzadbanifatemi.com/security-audit/what-is-auditing-when-it-comes-to-web-security</link>
		<comments>http://networksecurity.farzadbanifatemi.com/security-audit/what-is-auditing-when-it-comes-to-web-security#comments</comments>
		<pubDate>Wed, 31 Mar 2010 13:23:34 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security Audit]]></category>

		<guid isPermaLink="false">http://networksecurity.farzadbanifatemi.com/security-audit/what-is-auditing-when-it-comes-to-web-security</guid>
		<description><![CDATA[
Auditing = checking or verifying
Need any other definition?




]]></description>
			<content:encoded><![CDATA[<p>
<br />Auditing = checking or verifying</p>
<p>Need any other definition?</p>

<!-- start wp-tags-to-technorati 1.01 -->

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://networksecurity.farzadbanifatemi.com/security-audit/what-is-auditing-when-it-comes-to-web-security/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Is this true about not being able to audit &#8211; not just the Fed but the dept of TREASURY etc?</title>
		<link>http://networksecurity.farzadbanifatemi.com/security-audit/is-this-true-about-not-being-able-to-audit-not-just-the-fed-but-the-dept-of-treasury-etc</link>
		<comments>http://networksecurity.farzadbanifatemi.com/security-audit/is-this-true-about-not-being-able-to-audit-not-just-the-fed-but-the-dept-of-treasury-etc#comments</comments>
		<pubDate>Thu, 18 Mar 2010 03:23:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security Audit]]></category>

		<guid isPermaLink="false">http://networksecurity.farzadbanifatemi.com/security-audit/is-this-true-about-not-being-able-to-audit-not-just-the-fed-but-the-dept-of-treasury-etc</guid>
		<description><![CDATA[&#34; The Defense Department’s eschewal of economic reality finds its counterpart in its disinterest in accountability.  The dramatic admission of this statement of priorities came from Former Defense Secretary Donald Rumsfeld who admitted publicly that that DOD could not find $2.3 trillion.  The money is still missing.  (“The War on Waste: Defense [...]]]></description>
			<content:encoded><![CDATA[<p>&quot; The Defense Department’s eschewal of economic reality finds its counterpart in its disinterest in accountability.  The dramatic admission of this statement of priorities came from Former Defense Secretary Donald Rumsfeld who admitted publicly that that DOD could not find $2.3 trillion.  The money is still missing.  (“The War on Waste: Defense Department Cannot Account for 25% of Funds &#8211; $2.3 Trillion, CBS Evening News, January 29, 2002)</p>
<p>Future Defense chiefs won’t face such embarrassment. On May 8, 2009 the GAO informed the House Subcommittee on Government Management that six executive agencies can prohibit audits and investigations by the Inspector General &#8212; Defense, Treasury, Federal Reserve Board, Department of Justice, Homeland Security and the Postal Service and the CIA’s infamous and classified “Black budgets.” Accountability has now taken remote second place to “national security.”</p>
<p>http://www.hamsayeh.net/hamsayehnet_iran-international%20news995.htm</p>
<p>I have never seen this source before, so I don&#8217;t know how reliable it is, but I DID know of the $2+ trillion &#8216;lost&#8217; in defense in 2004 &#8212; is it true even the inspector general now can&#8217;t audit basic defense contracts, and the TREASURY???<br />
LTM, oh, I agree there is a clear agenda to the article, and I never heard of them before.  But they have sources sited for some of their stuff, so I think this may be true. Felonius seems to think so.  How you put the data together is a separate matter.<br />
<br />Disturbing if true.</p>

<!-- start wp-tags-to-technorati 1.01 -->

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://networksecurity.farzadbanifatemi.com/security-audit/is-this-true-about-not-being-able-to-audit-not-just-the-fed-but-the-dept-of-treasury-etc/feed</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>I have to do a security audit for a local credit union.?</title>
		<link>http://networksecurity.farzadbanifatemi.com/security-audit/i-have-to-do-a-security-audit-for-a-local-credit-union</link>
		<comments>http://networksecurity.farzadbanifatemi.com/security-audit/i-have-to-do-a-security-audit-for-a-local-credit-union#comments</comments>
		<pubDate>Tue, 16 Mar 2010 02:28:25 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security Audit]]></category>

		<guid isPermaLink="false">http://networksecurity.farzadbanifatemi.com/security-audit/i-have-to-do-a-security-audit-for-a-local-credit-union</guid>
		<description><![CDATA[there are two offices headquarters downtown and a branch office on the east side of town.The headquarters has:ten Windows XP workstations,connected to a Windows server 2008 file server, ten Windows vista workstations, one Windows server 2008 RRAS server accessed by home workers after hours,one Windows server 2008 printer,one Linux database server,one Linux web server for [...]]]></description>
			<content:encoded><![CDATA[<p>there are two offices headquarters downtown and a branch office on the east side of town.The headquarters has:ten Windows XP workstations,connected to a Windows server 2008 file server, ten Windows vista workstations, one Windows server 2008 RRAS server accessed by home workers after hours,one Windows server 2008 printer,one Linux database server,one Linux web server for members to check their account balances online, one firewall where the network connects to the credit unions ISP via a T3 dedicated link.The east side office has five Windows XP workstations,connected to the headquarters office Windows Server 2008 server through T1 link. I need to describe any entry points(physical or data transmission related, or any situations that may constitute a security risks, also how can I better train the employees to understand network security.<br />
<br />No disrespect, my friend, but if you need to come onto a public forum to ask this question, you do not appear qualified to conduct a security audit</p>

<!-- start wp-tags-to-technorati 1.01 -->

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://networksecurity.farzadbanifatemi.com/security-audit/i-have-to-do-a-security-audit-for-a-local-credit-union/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Bandolier: Security Audit Files for Control System Applications</title>
		<link>http://networksecurity.farzadbanifatemi.com/security-audit/bandolier-security-audit-files-for-control-system-applications</link>
		<comments>http://networksecurity.farzadbanifatemi.com/security-audit/bandolier-security-audit-files-for-control-system-applications#comments</comments>
		<pubDate>Sat, 13 Mar 2010 17:32:37 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security Audit]]></category>
		<category><![CDATA[Bandolier]]></category>

		<guid isPermaLink="false">http://networksecurity.farzadbanifatemi.com/security-audit/bandolier-security-audit-files-for-control-system-applications</guid>
		<description><![CDATA[Learn how Bandolier and the Nessus vulnerability scanner can help audit security configuration of your control system servers and workstations.
Duration : 0:8:33
[youtube C9unhYfIfuU]



Technorati Tags: Bandolier


]]></description>
			<content:encoded><![CDATA[<p><img src="http://i.ytimg.com/vi/C9unhYfIfuU/2.jpg" align="left">Learn how Bandolier and the Nessus vulnerability scanner can help audit security configuration of your control system servers and workstations.</p>
<p>Duration : <b>0:8:33</b></p>
<p><span id="more-934"></span><br />[youtube C9unhYfIfuU]</p>

<!-- start wp-tags-to-technorati 1.01 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/Bandolier' rel='tag' target='_blank'>Bandolier</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://networksecurity.farzadbanifatemi.com/security-audit/bandolier-security-audit-files-for-control-system-applications/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CISA audit process part 1 last</title>
		<link>http://networksecurity.farzadbanifatemi.com/security-audit/cisa-audit-process-part-1-last</link>
		<comments>http://networksecurity.farzadbanifatemi.com/security-audit/cisa-audit-process-part-1-last#comments</comments>
		<pubDate>Fri, 12 Mar 2010 01:27:13 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security Audit]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[certification]]></category>
		<category><![CDATA[cisa]]></category>
		<category><![CDATA[cism]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://networksecurity.farzadbanifatemi.com/security-audit/cisa-audit-process-part-1-last</guid>
		<description><![CDATA[This is the last video on IS audit process part 1. For full part 1 video visit:
cisa-2007.blogspot.com
join like-minded people to discuss about this exam :
http://r.yuwie.com/jyeesg
Duration : 0:1:28
[youtube plHfRBUNHEk]



Technorati Tags: audit, certification, cisa, cism, Compliance, security


]]></description>
			<content:encoded><![CDATA[<p><img src="http://i.ytimg.com/vi/plHfRBUNHEk/2.jpg" align="left">This is the last video on IS audit process part 1. For full part 1 video visit:<br />
cisa-2007.blogspot.com</p>
<p>join like-minded people to discuss about this exam :<br />
http://r.yuwie.com/jyeesg</p>
<p>Duration : <b>0:1:28</b></p>
<p><span id="more-928"></span><br />[youtube plHfRBUNHEk]</p>

<!-- start wp-tags-to-technorati 1.01 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/audit' rel='tag' target='_blank'>audit</a>, <a class='technorati-link' href='http://technorati.com/tag/certification' rel='tag' target='_blank'>certification</a>, <a class='technorati-link' href='http://technorati.com/tag/cisa' rel='tag' target='_blank'>cisa</a>, <a class='technorati-link' href='http://technorati.com/tag/cism' rel='tag' target='_blank'>cism</a>, <a class='technorati-link' href='http://technorati.com/tag/Compliance' rel='tag' target='_blank'>Compliance</a>, <a class='technorati-link' href='http://technorati.com/tag/security' rel='tag' target='_blank'>security</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://networksecurity.farzadbanifatemi.com/security-audit/cisa-audit-process-part-1-last/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Event ID 680 Failure Audit?</title>
		<link>http://networksecurity.farzadbanifatemi.com/security-audit/event-id-680-failure-audit</link>
		<comments>http://networksecurity.farzadbanifatemi.com/security-audit/event-id-680-failure-audit#comments</comments>
		<pubDate>Mon, 01 Mar 2010 01:31:36 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security Audit]]></category>

		<guid isPermaLink="false">http://networksecurity.farzadbanifatemi.com/security-audit/event-id-680-failure-audit</guid>
		<description><![CDATA[I am missing some files on my computer. I checked event viewer and saw under the security tab that I have a Failed Audit/Account Logon, event ID 680 0X0000064. I was wondering if this is anything to worry about. The computer that it failed with is another computer inside my works network. Could they be [...]]]></description>
			<content:encoded><![CDATA[<p>I am missing some files on my computer. I checked event viewer and saw under the security tab that I have a Failed Audit/Account Logon, event ID 680 0X0000064. I was wondering if this is anything to worry about. The computer that it failed with is another computer inside my works network. Could they be accessing my computer somehow?<br />
<br />There is some info about it at http://forums.techarena.in/windows-server-help/621166.htm The post is from 2006 ,but might put you in the right direction.</p>

<!-- start wp-tags-to-technorati 1.01 -->

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://networksecurity.farzadbanifatemi.com/security-audit/event-id-680-failure-audit/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>G4S begins staff audit</title>
		<link>http://networksecurity.farzadbanifatemi.com/security-audit/g4s-begins-staff-audit</link>
		<comments>http://networksecurity.farzadbanifatemi.com/security-audit/g4s-begins-staff-audit#comments</comments>
		<pubDate>Wed, 24 Feb 2010 23:41:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security Audit]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[begins]]></category>
		<category><![CDATA[G4S]]></category>
		<category><![CDATA[staff]]></category>

		<guid isPermaLink="false">http://networksecurity.farzadbanifatemi.com/security-audit/g4s-begins-staff-audit</guid>
		<description><![CDATA[Troubled security firm G4S is now alleging that an organized external criminal gang is behind the spate of robberies affecting its fleet. And as Yassin Juma reports, the security firm today ran a lie test on its employees as it moves to tackle the serious image crisis.
Duration : 0:1:53
[youtube h7ZrmZeSC1s]



Technorati Tags: audit, begins, G4S, staff


]]></description>
			<content:encoded><![CDATA[<p><img src="http://i.ytimg.com/vi/h7ZrmZeSC1s/2.jpg" align="left">Troubled security firm G4S is now alleging that an organized external criminal gang is behind the spate of robberies affecting its fleet. And as Yassin Juma reports, the security firm today ran a lie test on its employees as it moves to tackle the serious image crisis.</p>
<p>Duration : <b>0:1:53</b></p>
<p><span id="more-882"></span><br />[youtube h7ZrmZeSC1s]</p>

<!-- start wp-tags-to-technorati 1.01 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/audit' rel='tag' target='_blank'>audit</a>, <a class='technorati-link' href='http://technorati.com/tag/begins' rel='tag' target='_blank'>begins</a>, <a class='technorati-link' href='http://technorati.com/tag/G4S' rel='tag' target='_blank'>G4S</a>, <a class='technorati-link' href='http://technorati.com/tag/staff' rel='tag' target='_blank'>staff</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://networksecurity.farzadbanifatemi.com/security-audit/g4s-begins-staff-audit/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>

