<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>PowerTech PowerBlog &#187; Auditing</title>
	<atom:link href="http://www.powertechblog.com/category/auditing/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.powertechblog.com</link>
	<description></description>
	<lastBuildDate>Wed, 28 Jul 2010 14:26:33 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Using Authority Broker to Audit Yourself</title>
		<link>http://www.powertechblog.com/2010/07/14/using-authority-broker-to-audit-yourself/</link>
		<comments>http://www.powertechblog.com/2010/07/14/using-authority-broker-to-audit-yourself/#comments</comments>
		<pubDate>Wed, 14 Jul 2010 19:28:45 +0000</pubDate>
		<dc:creator>Robin</dc:creator>
				<category><![CDATA[Auditing]]></category>
		<category><![CDATA[Other]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.powertechblog.com/?p=479</guid>
		<description><![CDATA[I had a customer ask me recently if you could audit yourself in PowerTech’s Authority Broker tool. I responded, “Of course!” It seems that the auditors within this particular company wanted to ensure that all the powerful profiles were audited, but the I.T. department was resisting. Their main concern was that they didn’t have a [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.powertechblog.com%2F2010%2F07%2F14%2Fusing-authority-broker-to-audit-yourself%2F"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.powertechblog.com%2F2010%2F07%2F14%2Fusing-authority-broker-to-audit-yourself%2F" height="61" width="51" /></a></div><p>I had a customer ask me recently if you could audit yourself in PowerTech’s Authority Broker tool. I responded, “Of course!” It seems that the auditors within this particular company wanted to ensure that all the powerful profiles were audited, but the I.T. department was resisting. Their main concern was that they didn’t have a good way to deal with finding and deciphering all of the raw audit records that the operating system places into the audit journal when performing profile auditing.</p>
<p>Fortunately, this customer was already making extensive use of <a href="http://www.powertech.com/powertech/PowerTech_Web_AuthorityBroker.asp">Authority Broker</a> to handle elevation of authority for “break-glass” type emergency situations. In their shop, there were also certain functions that had to be run using specific profiles like QSECOFR, not just a profile running under the guise of QSECOFR. The solution was very simple: Install an Authority Broker PTF to enhance the base product, and permit the ability for a profile to switch to itself, thereby creating the audit and reporting environment that they were already familiar with when using normal profile switching.</p>
<p>We occasionally get notes about creative ways that customers wish to use one of our products—sometimes in ways that our development team never originally anticipated. While the base functionality of the products satisfies the vast majority of auditors’ requirements for regulatory compliance, we welcome “wish lists” and suggestions of how we can enhance any of our solutions. Simply send a note about your idea to <a href="mailto:support@powertech.com">support@powertech.com</a> to get your idea added into an enhancement list database. In this particular case, we already had this little trick up our sleeve, but we love to get ideas from those of you who have found requirements to use the tool in ways outside of the original scope. Another suggestion that was turned into reality was the ability to invoke exit programs as part of an Authority Broker swap. What? You didn’t know about that capability either?  Well, check out the administrator’s guide, and the sample exit programs found on the PowerTech <a href="http://www.powertech.com/">website</a>.</p>
<p>If you are new to Authority Broker, or would simply like to brush up on your skills, we are in the process of putting together a product eTraining class that will be rolled out at the beginning of September.</p>
<p>Drop me a line at <a href="mailto:robin.tatam@powertech.com">robin.tatam@powertech.com</a> for more information about PowerTech, or visit <a href="http://www.powertech.com/">www.powertech.com</a>.</p>
<p>Cheers!</p>
<p>- rt<strong><br />
</strong></p>


<!-- Begin SexyBookmarks Menu Code -->
<div class="sexy-bookmarks sexy-bookmarks-expand">
<ul class="socials">
		<li class="sexy-delicious">
			<a href="http://del.icio.us/post?url=http://www.powertechblog.com/2010/07/14/using-authority-broker-to-audit-yourself/&amp;title=Using+Authority+Broker+to+Audit+Yourself" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="sexy-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.powertechblog.com/2010/07/14/using-authority-broker-to-audit-yourself/&amp;title=Using+Authority+Broker+to+Audit+Yourself" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="sexy-reddit">
			<a href="http://reddit.com/submit?url=http://www.powertechblog.com/2010/07/14/using-authority-broker-to-audit-yourself/&amp;title=Using+Authority+Broker+to+Audit+Yourself" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="sexy-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.powertechblog.com/2010/07/14/using-authority-broker-to-audit-yourself/&amp;title=Using+Authority+Broker+to+Audit+Yourself" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="sexy-technorati">
			<a href="http://technorati.com/faves?add=http://www.powertechblog.com/2010/07/14/using-authority-broker-to-audit-yourself/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="sexy-twitter">
			<a href="http://twitter.com/home?status=Using+Authority+Broker+to+Audit+Yourself+-+http://www.powertechblog.com/2010/07/14/using-authority-broker-to-audit-yourself/+(via+@PowerTechGroup)" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="sexy-comfeed">
			<a href="http://www.powertechblog.com/2010/07/14/using-authority-broker-to-audit-yourself/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="sexy-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.powertechblog.com/2010/07/14/using-authority-broker-to-audit-yourself/&amp;title=Using+Authority+Broker+to+Audit+Yourself&amp;summary=I%20had%20a%20customer%20ask%20me%20recently%20if%20you%20could%20audit%20yourself%20in%20PowerTech%E2%80%99s%20Authority%20Broker%20tool.%20I%20responded%2C%20%E2%80%9COf%20course%21%E2%80%9D%20It%20seems%20that%20the%20auditors%20within%20this%20particular%20company%20wanted%20to%20ensure%20that%20all%20the%20powerful%20profiles%20were%20audited%2C%20but%20the%20I.T.%20department%20was%20resisting.%20Their%20main&amp;source=PowerTech PowerBlog" rel="nofollow" class="external" title="Share this on Linkedin">Share this on Linkedin</a>
		</li>
		<li class="sexy-google">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.powertechblog.com/2010/07/14/using-authority-broker-to-audit-yourself/&amp;title=Using+Authority+Broker+to+Audit+Yourself" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>
<!-- End SexyBookmarks Menu Code -->

]]></content:encoded>
			<wfw:commentRss>http://www.powertechblog.com/2010/07/14/using-authority-broker-to-audit-yourself/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What Comes First: Security or Compliance?</title>
		<link>http://www.powertechblog.com/2010/04/28/what-comes-first-security-or-compliance/</link>
		<comments>http://www.powertechblog.com/2010/04/28/what-comes-first-security-or-compliance/#comments</comments>
		<pubDate>Wed, 28 Apr 2010 15:17:23 +0000</pubDate>
		<dc:creator>Robin</dc:creator>
				<category><![CDATA[Auditing]]></category>
		<category><![CDATA[Other]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.powertechblog.com/?p=368</guid>
		<description><![CDATA[I am sometimes asked to clarify whether PowerTech is a security company or a compliance company. I also sometimes read comments from industry experts criticizing organizations for wasting time, effort, and money on compliance solutions without ever really becoming secure. Well, before I can weigh in on that argument, we have to discuss the basic [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.powertechblog.com%2F2010%2F04%2F28%2Fwhat-comes-first-security-or-compliance%2F"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.powertechblog.com%2F2010%2F04%2F28%2Fwhat-comes-first-security-or-compliance%2F" height="61" width="51" /></a></div><p>I am sometimes asked to clarify whether PowerTech is a security company or a compliance company. I also sometimes read comments from industry experts criticizing organizations for wasting time, effort, and money on compliance solutions without ever really becoming secure. Well, before I can weigh in on that argument, we have to discuss the basic difference between “security” and “compliance.”</p>
<p>Security is the act of creating a defense to prevent something from being attacked or injured. In the IT world, this usually pertains to preventing unauthorized access to computer servers, and more importantly, the application data that resides on them. For most businesses, the value of the technology infrastructure is found in the application data as hardware can be replaced relatively easily. Data is usually our primary intellectual property, for example: our customer information, order history, vendor data, employee information, and credit card transactions. Securing the data asset is necessary to prevent damage—both accidental and malicious—and to ensure that the data remains the property of the organization that owns it, and to allow it to add value to the buiness operations.</p>
<p><strong><span style="text-decoration: underline;"> </span></strong></p>
<p>Although obviously tied to security, compliance is simply the adherence (and proof of aderence) to a set of baseline standards and procedures. While you can be secure without being compliant, and even be compliant without truly being secure, the terms are often used interchangeably. When I consult with PowerTech customers, I am usually asked to help achieve compliance, often with Sarbanes-Oxley, or the payment card industry’s PCI-DSS standards. However, sometimes it is a worthwhile investment of time and money to set the compliance objective aside, and to simply review how <em>secure</em> you actually are.</p>
<p>Unfortunately (or thankfully, depending on your perspective!), it is not difficult to satisfy an auditor during an IBM i audit due to the fact that many of them really are not trained in auditing the i platform. While this sometimes leads to answering questions that don’t really pertain to us, it also means that we can potentially talk our way out of a compliance violation. Getting the auditors off our backs may seem advantageous in the short term, but it may be doing the organization a huge disservice in the long term.</p>
<p>One of the challenges is to educate customers that security is NOT a destination, but more of a journey. You can never really be 100% secure. There are new threats making security a continuously moving target, but regular compliance checks can help the server remain as secure as possible by assessing the risk of threats, and the vulnerability that you could become subjected to it. But in order to do that, we have to accept a valid set of standards as our baseline.</p>
<p>So, back to our original question: Is PowerTech a security or a compliance company? Well, I say that we provide solutions that can align with both security <em>and</em> compliance objectives. Network Security’s access control facility, and Authority Broker’s restriction on powerful users, are both designed to provide tangible value to an organization’s security defenses. Compliance Monitor, a compliance tool per se, provides visibility into the security audit journal to enable security officers to respond in a more timely manner to possible intrusion events. These tools can also help satisfy common compliance criteria. For example, Network Security can satisfy a compliance requirement such as “audit and control access for network initiated activities,” and Compliance Monitor can generate compliance scorecards to compare security policy to current settings.</p>
<p>In summary, I am a proponent of working to secure a system and data from common and known vulnerabilities <em>first</em>. This typically involves an audit of configuration and procedures against best-practices, the creation and maintenance of a detailed security policy. Once you do that, you can work to secure your environment using the policy as your guideline. Then you can “simply” monitor for ongoing compliance to your objectives and standards. PowerTech can help you navigate through the entire project cycle!</p>
<p>Have a wonderful week!</p>
<p>- rt</p>


<!-- Begin SexyBookmarks Menu Code -->
<div class="sexy-bookmarks sexy-bookmarks-expand">
<ul class="socials">
		<li class="sexy-delicious">
			<a href="http://del.icio.us/post?url=http://www.powertechblog.com/2010/04/28/what-comes-first-security-or-compliance/&amp;title=What+Comes+First%3A+Security+or+Compliance%3F" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="sexy-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.powertechblog.com/2010/04/28/what-comes-first-security-or-compliance/&amp;title=What+Comes+First%3A+Security+or+Compliance%3F" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="sexy-reddit">
			<a href="http://reddit.com/submit?url=http://www.powertechblog.com/2010/04/28/what-comes-first-security-or-compliance/&amp;title=What+Comes+First%3A+Security+or+Compliance%3F" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="sexy-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.powertechblog.com/2010/04/28/what-comes-first-security-or-compliance/&amp;title=What+Comes+First%3A+Security+or+Compliance%3F" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="sexy-technorati">
			<a href="http://technorati.com/faves?add=http://www.powertechblog.com/2010/04/28/what-comes-first-security-or-compliance/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="sexy-twitter">
			<a href="http://twitter.com/home?status=What+Comes+First%3A+Security+or+Compliance%3F+-+http://www.powertechblog.com/2010/04/28/what-comes-first-security-or-compliance/+(via+@PowerTechGroup)" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="sexy-comfeed">
			<a href="http://www.powertechblog.com/2010/04/28/what-comes-first-security-or-compliance/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="sexy-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.powertechblog.com/2010/04/28/what-comes-first-security-or-compliance/&amp;title=What+Comes+First%3A+Security+or+Compliance%3F&amp;summary=I%20am%20sometimes%20asked%20to%20clarify%20whether%20PowerTech%20is%20a%20security%20company%20or%20a%20compliance%20company.%20I%20also%20sometimes%20read%20comments%20from%20industry%20experts%20criticizing%20organizations%20for%20wasting%20time%2C%20effort%2C%20and%20money%20on%20compliance%20solutions%20without%20ever%20really%20becoming%20secure.%20Well%2C%20before%20I%20can%20weigh%20in&amp;source=PowerTech PowerBlog" rel="nofollow" class="external" title="Share this on Linkedin">Share this on Linkedin</a>
		</li>
		<li class="sexy-google">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.powertechblog.com/2010/04/28/what-comes-first-security-or-compliance/&amp;title=What+Comes+First%3A+Security+or+Compliance%3F" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>
<!-- End SexyBookmarks Menu Code -->

]]></content:encoded>
			<wfw:commentRss>http://www.powertechblog.com/2010/04/28/what-comes-first-security-or-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>On the Last Day of Christmas, PowerTech gave to me …</title>
		<link>http://www.powertechblog.com/2009/12/22/on-the-last-day-of-christmas-powertech-gave-to-me-%e2%80%a6/</link>
		<comments>http://www.powertechblog.com/2009/12/22/on-the-last-day-of-christmas-powertech-gave-to-me-%e2%80%a6/#comments</comments>
		<pubDate>Tue, 22 Dec 2009 14:54:57 +0000</pubDate>
		<dc:creator>Robin</dc:creator>
				<category><![CDATA[Auditing]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.powertechblog.com/?p=206</guid>
		<description><![CDATA[It is amazing to me that another year is already coming to an end. With the mad dash of last minute shoppers (yes, that would be me this year!), and the certainty of a white Christmas for us in much of the Midwest, it is definitely going out with a bang. In fact, although Winter [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.powertechblog.com%2F2009%2F12%2F22%2Fon-the-last-day-of-christmas-powertech-gave-to-me-%25e2%2580%25a6%2F"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.powertechblog.com%2F2009%2F12%2F22%2Fon-the-last-day-of-christmas-powertech-gave-to-me-%25e2%2580%25a6%2F" height="61" width="51" /></a></div><p>It is amazing to me that another year is already coming to an end. With the mad dash of last minute shoppers (yes, that would be me this year!), and the certainty of a white Christmas for us in much of the Midwest, it is definitely going out with a bang. In fact, although Winter officially began yesterday, the readers of this blog will know that we have been feeling it in Minneapolis for several weeks. December 21st is marked as Winter Solstice—the shortest day of the year due to the Earth’s tilt—so the good news is that summer is on its way. Ok, so I’m an eternal optimist!</p>
<p>In the spirit of the season, I thought I would create a last-minute holiday wish-list for the security officers that made Santa’s “good” list:</p>
<p><strong>Perform an assessment</strong></p>
<p>This is a good way to get the baseline metrics reviewed; identify the areas of weakness and strength so you can focus your resources where they are needed.</p>
<p>This one is a stocking stuffer, as PowerTech does it for free!</p>
<p><strong>Create a policy</strong></p>
<p>It is hard to measure your progress without a policy. You can even start with the open-source one at www.powertech.com!</p>
<p><strong>Update your system values</strong></p>
<p>Make sure that the server configuration reflects the directives in your security policy. After you set the correct attributes, use the policy feature of PowerTech Compliance Monitor to validate that nothing has changed with scorecard views of system value compliance.</p>
<p><strong>Secure Your Borders</strong></p>
<p>Internal employees are the cause of approximately 70% of data integrity events. Ensure that you don’t secure just your perimeter and leave corporate users with unrestricted network access. Any user with access to your servers should be audited and controlled. PowerTech’s Network Security provides both auditing and access control of powerful interfaces like FTP, ODBC, and remote command.</p>
<p><strong>Don’t overlook your powerful users</strong></p>
<p>Sure, we expect our programmers and administrators to run and maintain a system, but would we want them to have our social security numbers, bank balances, and the “skeleton key” to our corporate data? Try to reduce unnecessary assignment of special authorities, and then use a tool like PowerTech Authority Broker to facilitate on-demand access to super-users while auditing their activities.</p>
<p><strong>Educate your staff</strong></p>
<p>PowerTech conducts weekly online Webinars, as well as eTraining. In 2010, we are also taking some classes out on the road. Registration for the eTraining will open shortly at www.powertech.com. Get on our newsletter list while you are there and stay informed of events, as well as related security news and articles specific to IBM i.</p>
<p>We know that taking that first step can sometimes be a daunting one. If you are not sure how to get started, allow our team here to guide your compliance sleigh!  After all, we have being doing it for years.</p>
<p>Happy Holidays!!</p>


<!-- Begin SexyBookmarks Menu Code -->
<div class="sexy-bookmarks sexy-bookmarks-expand">
<ul class="socials">
		<li class="sexy-delicious">
			<a href="http://del.icio.us/post?url=http://www.powertechblog.com/2009/12/22/on-the-last-day-of-christmas-powertech-gave-to-me-%e2%80%a6/&amp;title=On+the+Last+Day+of+Christmas%2C+PowerTech+gave+to+me+%E2%80%A6" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="sexy-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.powertechblog.com/2009/12/22/on-the-last-day-of-christmas-powertech-gave-to-me-%e2%80%a6/&amp;title=On+the+Last+Day+of+Christmas%2C+PowerTech+gave+to+me+%E2%80%A6" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="sexy-reddit">
			<a href="http://reddit.com/submit?url=http://www.powertechblog.com/2009/12/22/on-the-last-day-of-christmas-powertech-gave-to-me-%e2%80%a6/&amp;title=On+the+Last+Day+of+Christmas%2C+PowerTech+gave+to+me+%E2%80%A6" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="sexy-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.powertechblog.com/2009/12/22/on-the-last-day-of-christmas-powertech-gave-to-me-%e2%80%a6/&amp;title=On+the+Last+Day+of+Christmas%2C+PowerTech+gave+to+me+%E2%80%A6" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="sexy-technorati">
			<a href="http://technorati.com/faves?add=http://www.powertechblog.com/2009/12/22/on-the-last-day-of-christmas-powertech-gave-to-me-%e2%80%a6/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="sexy-twitter">
			<a href="http://twitter.com/home?status=On+the+Last+Day+of+Christmas%2C+PowerTech+gave+to+me+%E2%80%A6+-+http://www.powertechblog.com/2009/12/22/on-the-last-day-of-christmas-powertech-gave-to-me-%e2%80%a6/+(via+@PowerTechGroup)" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="sexy-comfeed">
			<a href="http://www.powertechblog.com/2009/12/22/on-the-last-day-of-christmas-powertech-gave-to-me-…/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="sexy-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.powertechblog.com/2009/12/22/on-the-last-day-of-christmas-powertech-gave-to-me-%e2%80%a6/&amp;title=On+the+Last+Day+of+Christmas%2C+PowerTech+gave+to+me+%E2%80%A6&amp;summary=It%20is%20amazing%20to%20me%20that%20another%20year%20is%20already%20coming%20to%20an%20end.%20With%20the%20mad%20dash%20of%20last%20minute%20shoppers%20%28yes%2C%20that%20would%20be%20me%20this%20year%21%29%2C%20and%20the%20certainty%20of%20a%20white%20Christmas%20for%20us%20in%20much%20of%20the%20Midwest%2C%20it%20is%20definitely%20going%20out%20with%20a%20bang.%20In%20fact%2C%20although%20Winter%20officially%20began%20yes&amp;source=PowerTech PowerBlog" rel="nofollow" class="external" title="Share this on Linkedin">Share this on Linkedin</a>
		</li>
		<li class="sexy-google">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.powertechblog.com/2009/12/22/on-the-last-day-of-christmas-powertech-gave-to-me-%e2%80%a6/&amp;title=On+the+Last+Day+of+Christmas%2C+PowerTech+gave+to+me+%E2%80%A6" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>
<!-- End SexyBookmarks Menu Code -->

]]></content:encoded>
			<wfw:commentRss>http://www.powertechblog.com/2009/12/22/on-the-last-day-of-christmas-powertech-gave-to-me-%e2%80%a6/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Don’t Gamble with Your Audit</title>
		<link>http://www.powertechblog.com/2009/10/13/don%e2%80%99t-gamble-with-your-audit/</link>
		<comments>http://www.powertechblog.com/2009/10/13/don%e2%80%99t-gamble-with-your-audit/#comments</comments>
		<pubDate>Tue, 13 Oct 2009 09:08:37 +0000</pubDate>
		<dc:creator>Robin</dc:creator>
				<category><![CDATA[Auditing]]></category>

		<guid isPermaLink="false">http://www.powertechblog.com/?p=45</guid>
		<description><![CDATA[It’s always an eye-opening experience to speak with an auditor about the intricacies of auditing an IT environment. I respect their views, and I can only imagine how difficult it is trying to be an expert on the wide variety of technologies found in an average enterprise.
Last week, I spent a couple of days at [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.powertechblog.com%2F2009%2F10%2F13%2Fdon%25e2%2580%2599t-gamble-with-your-audit%2F"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.powertechblog.com%2F2009%2F10%2F13%2Fdon%25e2%2580%2599t-gamble-with-your-audit%2F" height="61" width="51" /></a></div><p>It’s always an eye-opening experience to speak with an auditor about the intricacies of auditing an IT environment. I respect their views, and I can only imagine how difficult it is trying to be an expert on the wide variety of technologies found in an average enterprise.</p>
<p>Last week, I spent a couple of days at the ISACA conference in Las Vegas, meeting and talking with auditors from around the country. While some had heard of the System i (or iSeries or AS/400), it was very evident that there weren’t any subject matter experts on hand. I was left wondering: “How can anyone receive an effective audit of a platform that IT auditors have such limited knowledge of?”</p>
<p>PowerTech security experts perform a healthy number of audits each year, but there are not many firms with our professional capabilities. Yet, we’re barely scratching the surface of the immense number of organizations that must maintain compliance with the seemingly-endless list of regulations and legislations found throughout the world. What about the others—are they just ignoring the mandates? Or, are they being subjected to questionable recommendations made from a comparison to an old checklist compiled from numerous online sources. I fear it’s probably a mix of the two!</p>
<p>PowerTech developed the wildly popular Compliance Assessment tool to perform a review of six major areas of vulnerability. We have made this tool available to users as a free service, and now include one-on-one time with a security expert to help interpret the findings. The auditors I talked to were extremely excited to know that there was someone out there to help make their lives easier, and to be an expert they can talk to when they encounter a System i. I’m excited and encouraged at the opportunities that brings to the PowerTech table as we continue to grow, and as we continue to service the IBM i community with world-class security solutions.</p>
<p>While you might not think of an IBM i-savvy auditor as a benefit, the fact that you’re talking with someone who understands real-world vulnerabilities, as well as the inherent strengths of security on the platform, adds protection to your corporate data. And the availability of a speedy tool that provides an educated view into the infrastructure makes your IBM i data even safer.</p>
<p>And, after all, isn’t that the purpose of a security audit in the first place?</p>


<!-- Begin SexyBookmarks Menu Code -->
<div class="sexy-bookmarks sexy-bookmarks-expand">
<ul class="socials">
		<li class="sexy-delicious">
			<a href="http://del.icio.us/post?url=http://www.powertechblog.com/2009/10/13/don%e2%80%99t-gamble-with-your-audit/&amp;title=Don%E2%80%99t+Gamble+with+Your+Audit" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="sexy-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.powertechblog.com/2009/10/13/don%e2%80%99t-gamble-with-your-audit/&amp;title=Don%E2%80%99t+Gamble+with+Your+Audit" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="sexy-reddit">
			<a href="http://reddit.com/submit?url=http://www.powertechblog.com/2009/10/13/don%e2%80%99t-gamble-with-your-audit/&amp;title=Don%E2%80%99t+Gamble+with+Your+Audit" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="sexy-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.powertechblog.com/2009/10/13/don%e2%80%99t-gamble-with-your-audit/&amp;title=Don%E2%80%99t+Gamble+with+Your+Audit" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="sexy-technorati">
			<a href="http://technorati.com/faves?add=http://www.powertechblog.com/2009/10/13/don%e2%80%99t-gamble-with-your-audit/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="sexy-twitter">
			<a href="http://twitter.com/home?status=Don%E2%80%99t+Gamble+with+Your+Audit+-++(via+@PowerTechGroup)" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="sexy-comfeed">
			<a href="http://www.powertechblog.com/2009/10/13/don’t-gamble-with-your-audit/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="sexy-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.powertechblog.com/2009/10/13/don%e2%80%99t-gamble-with-your-audit/&amp;title=Don%E2%80%99t+Gamble+with+Your+Audit&amp;summary=It%E2%80%99s%20always%20an%20eye-opening%20experience%20to%20speak%20with%20an%20auditor%20about%20the%20intricacies%20of%20auditing%20an%20IT%20environment.%20I%20respect%20their%20views%2C%20and%20I%20can%20only%20imagine%20how%20difficult%20it%20is%20trying%20to%20be%20an%20expert%20on%20the%20wide%20variety%20of%20technologies%20found%20in%20an%20average%20enterprise.%0D%0A%0D%0ALast%20week%2C%20I%20spent%20a%20c&amp;source=PowerTech PowerBlog" rel="nofollow" class="external" title="Share this on Linkedin">Share this on Linkedin</a>
		</li>
		<li class="sexy-google">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.powertechblog.com/2009/10/13/don%e2%80%99t-gamble-with-your-audit/&amp;title=Don%E2%80%99t+Gamble+with+Your+Audit" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>
<!-- End SexyBookmarks Menu Code -->

]]></content:encoded>
			<wfw:commentRss>http://www.powertechblog.com/2009/10/13/don%e2%80%99t-gamble-with-your-audit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
