<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Who should do your security audits? Or, how do you organize the security department?</title><link>http://blogs.technet.com/steriley/archive/2008/02/07/who-should-do-your-security-audits-or-how-do-you-organize-the-security-department.aspx</link><description>An interesting question came up today. The group responsible for configuring and maintaining the firewalls at a customer also believes that they should be the only ones to audit their configurations. Others in the security department are uneasy with this,</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: Who should do your security audits? Or, how do you organize the security department?</title><link>http://blogs.technet.com/steriley/archive/2008/02/07/who-should-do-your-security-audits-or-how-do-you-organize-the-security-department.aspx#2866274</link><pubDate>Mon, 11 Feb 2008 06:54:05 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2866274</guid><dc:creator>Shoaib Yousuf</dc:creator><description>&lt;p&gt;Hi Steve,&lt;/p&gt;
&lt;p&gt;The security standards group defines an organization’s security architecture and they will only be able to do it when they will understand the needs and drivers of the various business units. So, there shouldn’t be conflict between standards/alignment roles or you can say both roles are similar.&lt;/p&gt;
&lt;p&gt;I agree and liked your explanation on operations/auditing though….But, if auditors perform their task as you have defined then there will be no conflict in these two roles either…&lt;/p&gt;
&lt;p&gt;According to me it should be like this:&lt;/p&gt;
&lt;p&gt;Security Risk Management&lt;/p&gt;
&lt;p&gt;Security Alignment / standards&lt;/p&gt;
&lt;p&gt;Security Operations&lt;/p&gt;
&lt;p&gt;Security Auditing&lt;/p&gt;
&lt;p&gt;The reason why I have put standards after alignment is after understanding the needs and drivers of the various business units through risk management they will be able to work on standards which will later help security operations. In the end good auditing can help to ensure all policies are used appropriately.&lt;/p&gt;
&lt;p&gt;Cheers&lt;/p&gt;
&lt;p&gt;Shoaib&lt;/p&gt;
</description></item><item><title>re: Who should do your security audits? Or, how do you organize the security department?</title><link>http://blogs.technet.com/steriley/archive/2008/02/07/who-should-do-your-security-audits-or-how-do-you-organize-the-security-department.aspx#2898678</link><pubDate>Sat, 16 Feb 2008 15:55:39 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2898678</guid><dc:creator>antivirus</dc:creator><description>&lt;p&gt;Thank You For Sharin very inforamtive materials with us&lt;/p&gt;
</description></item></channel></rss>