Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Sarern
Nov 4, 2008

:toot:
Won't you take me to
Bomertown?
Won't you take me to
BONERTOWN?

:toot:

Martytoof posted:

Asked in the IT Cert thread but I'll check here too.

Anyone taken the CISA lately? Working on pivoting to audit and assurance a little more and I'm thinking of doing CISA in '18.

Mine came in a few months ago, but I took the exam like two years ago (had to wait on the experience requirement). My boss is working on hers right now.

Adbot
ADBOT LOVES YOU

Sarern
Nov 4, 2008

:toot:
Won't you take me to
Bomertown?
Won't you take me to
BONERTOWN?

:toot:

CommieGIR posted:

Hell, millions still use plane dictionary words. We had a load balancer get hit like that.

Plane dictionary words should be a pretty flat load though. No balancing required.

Sarern
Nov 4, 2008

:toot:
Won't you take me to
Bomertown?
Won't you take me to
BONERTOWN?

:toot:

Combat Pretzel posted:

lolwat

I sure hope you take notes, names, time and date, to rub it under their noses, when said hypothetical scenarios actually do happen. And to cover your rear end.

At an engagement I did years ago, we warned the client that their 'data center' (maybe 100 physical servers) was in the basement of a large, old building which had had water issues and that the data center had no mitigation or detection for water damage. They said "thanks but that's a hypothetical issue that is unlikely to affect us".

Less than a year later there was a fire on another floor. Although there were no sprinklers in the data center, the water from other floors went downhill, flooded their data center, and trashed everything.

Sarern
Nov 4, 2008

:toot:
Won't you take me to
Bomertown?
Won't you take me to
BONERTOWN?

:toot:

BangersInMyKnickers posted:

nah they'll be able to get that expunged since the charges were dismissed

I'm sure that will help some, but at a former engagement with a law enforcement client I had to get fingerprinted twice. Why? When I asked the client that, they said it was because they used the wrong code the first time; they meant to use the code that returns full results, including expunged results. Maybe they were just pulling my leg. I hope they were pulling my leg.

Sarern
Nov 4, 2008

:toot:
Won't you take me to
Bomertown?
Won't you take me to
BONERTOWN?

:toot:

Martytoof posted:

I’m sure most orgs will throw that on the biennial patch schedule right away.

E: can't spell

Sarern
Nov 4, 2008

:toot:
Won't you take me to
Bomertown?
Won't you take me to
BONERTOWN?

:toot:

Jeoh posted:

what the gently caress is the deal with auditors who want screenshots instead of console output?

Poor training or bad instructions from management which they're not willing to push back on, usually.

Sarern
Nov 4, 2008

:toot:
Won't you take me to
Bomertown?
Won't you take me to
BONERTOWN?

:toot:
Wanted: 5 years experience implementing version 8 of the CIS controls.

Sarern
Nov 4, 2008

:toot:
Won't you take me to
Bomertown?
Won't you take me to
BONERTOWN?

:toot:

navyjack posted:

I eventually want to get into GRC and audit

Every government audit shop in existence is perpetually trying to hire new auditors and train them up because they inevitably leave for more money within 3-5 years. Most state auditors have IT security audit teams and they are constantly losing people who are poached for internal GRC or IT audit roles at the places being audited. And if you really hate yourself, there's also working for the big 4.

Adbot
ADBOT LOVES YOU

Sarern
Nov 4, 2008

:toot:
Won't you take me to
Bomertown?
Won't you take me to
BONERTOWN?

:toot:

Combat Pretzel posted:


But specific customers wanting to audit on their own, is that actually a thing? Or is he misinterpreting some stuff? (He didn't know what NodeJS was, when we had our talk with IT about our things, so I'm wary about such claims.)


It can be! But I don't know how common it is.

Most commonly I've seen people just accept documentation like SOC-2 reports, but I have seen some places put a right to audit into their contracts. Either because they want that extra level of assurance regarding their software supply chain or because they are being forced to get that level of assurance (usually by some kind of oversight function that is remembering a giant fuckup.)

When I see organizations who don't have that kind of contractual language try to get audits of their vendor-provided IT services, most often the vendor simply ignores them or says no. Unless they're desperate to retain the contract, which sometimes happens depending on the relative sizes of the business units involved and the size of the contract.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply