Rants
Questions
Soapbox
Best Practices
Apply today for a FREE subscription to CIO Magazine!
Mon, Jun 29, 2009 11:59 EDT
|
Posted by: Anonymous in Best Practices Topic: Enterprise Management
Current Rating: |
By Gene Kim, CTO of Tripwire and co-founder of the IT Process Institute: If the auditor observes that no one is showing up to the change management meetings, authorizations are rubber stamped without any real evaluation, unauthorized changes and unplanned outages are occurring regularly, then she will likely flag this as a potential high risk area.
http://information-security-resources.com/2009/06/29/audits-and-the-change-management-process/