<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Audit on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/audit/</link>
    <description>Recent content in Audit on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Fri, 20 Oct 2023 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/audit/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Student Project - Audit Framework</title>
      <link>https://insinuator.net/2023/10/student-project-audit-framework/</link>
      <pubDate>Fri, 20 Oct 2023 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2023/10/student-project-audit-framework/</guid>
      <description>&lt;h2 id=&#34;introduction&#34;&gt;Introduction&lt;/h2&gt;&#xA;&lt;p&gt;In 2021, &lt;a href=&#34;https://www.ernw.de&#34;&gt;ERNW&lt;/a&gt; collaborated with&#xA;&lt;a href=&#34;https://www.hs-mannheim.de&#34;&gt;Hochschule Mannheim&lt;/a&gt; for their CEP (Cyber Security&#xA;Entwicklungsprojekt) to build an auditing framework for testing operating system&#xA;configurations against security procedures. This project is part of the&#xA;education program of the university to give the students the chance to utilize&#xA;the knowledge gained throughout the first semesters in a real world project.&#xA;ERNW posed as the fictitious customer, providing a requirements document and&#xA;regular meetings with all project groups for feedback. We planned to process and&#xA;adapt the results for an open source auditing framework. Unfortunately, we were&#xA;not able to finish this project yet, but we think the students should get some&#xA;attention for their work independent from our side. So here is a short summary&#xA;of what the students created and the corresponding repositories.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Auditing AWS Environments</title>
      <link>https://insinuator.net/2018/03/auditing-aws-environments/</link>
      <pubDate>Wed, 07 Mar 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/03/auditing-aws-environments/</guid>
      <description>&lt;h2 id=&#34;introduction&#34;&gt;Introduction&lt;/h2&gt;&#xA;&lt;p&gt;Related to our new TROOPERS workshop &lt;a href=&#34;https://troopers.de/troopers18/trainings/jfc3gg/&#34;&gt;“Jump-Starting Public Cloud Security”&lt;/a&gt;, this post is going to describe some relevant components which need to be taken care of when constructing and auditing an Amazon Web Services (AWS) cloud environment. Those include amongst others the general AWS account structure, Identity and Access Management (IAM), Auditing and Logging (CloudTrail and CloudWatch), Virtual Private Cloud (VPC) networks, as well as S3 buckets.&lt;/p&gt;&#xA;&lt;p&gt;The AWS IAM service is responsible for identity and access management (surprise!). This includes managing user accounts, defining password policies, and – most importantly – creating, defining, and assigning groups and roles.&lt;/p&gt;</description>
    </item>
    <item>
      <title>(Auditing) Remote Access Security in 2011</title>
      <link>https://insinuator.net/2011/08/auditing-remote-access-security-in-2011/</link>
      <pubDate>Sun, 14 Aug 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/08/auditing-remote-access-security-in-2011/</guid>
      <description>&lt;p&gt;I’m currently involved in a “Remote Access Security Assessment” and you might be wondering what exactly this means. Well, so did we. At least to some degree (btw: last year we provided some notes on types of security assessments &lt;a href=&#34;http://www.insinuator.net/2010/05/security-assessments/&#34;&gt;here&lt;/a&gt;).&lt;/p&gt;&#xA;&lt;p&gt;It happens quite often we’re brought into an organization to perform “a security assessment” of “some item” (“our network”, “that new procurement portal”, “the PKI” etc.). It happens as well the customer does not have a very clear idea of the way such an assessment should be carried out (telling us “you are the experts, you should know what to do”). Or the five people from the customer’s side present in the kick-off meeting have five different concepts (ok, four. as one of them only wants “to get that damned assessment done so we can finally go live”) and we end up moderating their arguments on what should be tested, how this should be done, when this is going to happen, which type of report format is needed (obviously, there’s different ones, depending on the goal/scope/methodology of the assessment…) etc.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
