Home > Ask the Networking Experts > Enterprise security with Michael Gregg Questions & Answers > What's the difference between a network assessment and an audit?
Ask The Networking Expert: Questions & Answers
EMAIL THIS

What's the difference between a network assessment and an audit?

Michael Gregg EXPERT RESPONSE FROM: Michael Gregg

Pose a Question
Other Networking Categories
Meet all Networking Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 04 October 2005
What?s the difference between a network assessment and an audit?

>
EXPERT RESPONSE
That's a good question. Let's start with some definitions as commonly found on the Web.

Educause.edu defines an assessment as "the process of identifying technical vulnerabilities in computers and networks as well as weaknesses in policies and practices relating to the operation of these systems."

TechTarget.com defines an audit as "a systematic evaluation of the security of a company's information system by measuring how well it conforms to a set of established criteria. Many times audits are often used to determine regulatory compliance, in the wake of legislation (such as HIPAA, the Sarbanes-Oxley Act, and the California Security Breach Information Act) that specifies how organizations must deal with information."

As you can see, these definitions are actually very similar. But one difference is that assessments can take on an adversarial role. One example would be "Eligible Receiver." This 1997 internal security assessment initiated by the Department of Defense was designed to simulate what a team of hackers could do if they targeted the Pentagon's computer system.

Audits do not typically take on such an adversarial role. While it's true that audits assess the strength and effectiveness of controls that are designed to protect information and safeguard assets, they usually look more at existing policy and controls. They also seek to determine if these policies are being followed by employees. When controls are not in compliance, the auditor may report who and what is not in compliance.

That brings us to a second difference between an assessment and an audit. Assessments tend to practice non-attribution.

Finally, while audits tend to measure performance against existing polices and best practices like HIPAA, the SOX's, and the California Security Breach Information Act, assessments go a step further and actually seek out vulnerabilities and may even exploit them. This is something you will not usually see during an audit.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Enterprise security with Michael Gregg
Why implementing adequate security challenges LAN administration
What security measures are recommended for each level of the TCP/IP model?
What are the best methods for handling rogue access points?
How to interpret test scan results to assess network vulnerability
What should I know before implementing a packet sniffer?
Will WPA2-PSK keep wireless networks safe from war drivers?
How to train intrusion detection systems (IDS)
Can a broadband network installer compromise your network security?
Do social networking products (blogs) pose network security threats?
What types of network firewalls are there?

Network Documentation
Networking data visualization not just for pointy-headed bosses
Virtual machines present dynamic environment issues for network pros
Network configuration management software boosts university networking
What is the document flow of enterprise-level network consulting?
As network configuration management matures, documentation woes linger
BICSI separation requirements between cross-connect points
Is there Cisco router documentation for proactive and reactive checklists?
What licenses allow user access to applications on the server?
To evaluate network management, what criteria is there?
How can I persuade my boss from letting users have administrative access to their machines?

Network Monitoring
Networking data visualization not just for pointy-headed bosses
What network security threat does a QM FSM error pose in IPsec VPNs?
Juniper updates Network and Security Manager to manage full portfolio
Network management software vendors readying IPv6
DNS management becoming critical to businesses but poorly understood
SolarWinds adds enterprise scalability to its network monitoring tool
Network forensics appliance gets storage boost and 10 GbE support
Tracking NetFlow over MPLS helps airline with compliance
When it comes to data loss prevention, networking should be part of the conversation
Network management takes interface tips from gaming industry, Google
Network Monitoring Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
DEN  (SearchNetworking.com)
run book  (SearchNetworking.com)
Service Location Protocol  (SearchNetworking.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Expert networking advice and tips for IT professionals
Visit KnowledgeStorm's comprehensive and easy to use business white paper directory.
HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersNetworking Product Trials
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2000 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts