Auditors choose profits over security

 

Study reveals oversights in Aussie organisations.

A university study of more than 400 Australian organisations has found them exposed to intruders through network routers and switches left misconfigured and unpatched.

Charles Sturt University teamed with penetration testers and security researchers for a three-year study of 1323 routers and 452 switches in organisations that handled credit cards and other sensitive information.

Researchers highligted gross oversights in security controls such as routers with default passwords, misconfigured network services and poor or absent access controls.

Only four percent of routers and 1.2 percent switches were patched and configured, they found.

It took organisations almost a year on average to patch switches; the devices were never tested by auditors who rarely examined the corresponding client software.

“Consequently, there is little incentive for the organisation under audit to maintain critical systems,” authors wrote.

Organisations had regular audits from “respectable” security firms and some were deemed compliant under the payment-card industry's data security standard and ISO 2700, a security-management standard.

But the industry's drive to the “lowest common denominator” meant organisations and auditors chose to overlook serious security flaws in the name of profits, said report author Craig Wright.

IT staff who had incentives tied to results would often “lie by omission” to pass the tests. And auditors would take their word rather than test and verify, which would treble the audit cost.

Auditors were "watchdogs and not bloodhounds", researchers wrote.

The risk from hacking left auditors “seeking the compliance tests that bring them the greatest returns with little risk of fallout when they fail”.

No auditor examined ther subjects' network-equipment firmware during the study and organisations were focused on getting the network auditor’s tick.

“It’s easier not to tackle the gaps and put a junior on the job,” Dr Wright said. “They know what needs to done to pass the audit and that’s what they focus on.”

Patch policy was present for servers and client operating systems but it took up to three months to fix server holes and 50 days to patch operating systems.

The policies were rarely required for network devices.

Operating system patches for client systems and firewalls were applied and tested within two months.

Wright scoffed at popular “tick-box” auditing arrangements, where networks were examined no more than every few months. Those arrangements were insufficient to ensure organisations were abreast of security vulnerabilities, he said.

“Spending money to demonstrate compliance does not in itself provide security.”

Government and commercial groups such as the Payment Card Industry were blamed in the report for inflating the importance of compliance schemes, company negligence rules and governance functions when reports to demonstrate compliance were used in place of a “real effort to ensure that data protection occurs”.

The focus of the legal system on “conventional, fault-based tort principles” (litigation) meant a favourable compliance report could absolve an organisation.

Audits should be done weekly and drill into a section of security, researchers wrote. Dr Wright said auditors big and small here and in Britain and the US were guilty.

He said the hallmark of a good auditor was integrity; they should be chosen based on a trial assessment of an organisation’s network and be instructed to test by information security frameworks such as OWASP that looked at web-application security.

“The practice of implementing monitoring controls that do not report on breaches but which do satisfy the compliance needs of an organisation can cost far more in the long term,” researchers concluded.

Copyright © SC Magazine, Australia


Auditors choose profits over security
Auditors are selling their customers short if they take their word for the security of their systems.
 
 
 
 
Top Stories
NBN Co could miss revised June fibre targets
Analysis: Cutting it fine in the race to the line.
 
Review: Sydney's Opal smartcard
It's no Oyster card.
 
Rackspace puts price premium on Aussie public cloud
At least 17 percent more compared to US instances.
 
 
Auditors are selling their customers short if they take their word for the security of their systems.
Sign up to receive iTnews email bulletins
   FOLLOW US...

Latest VideosSee all videos »

iTnews Academy: Microsoft Windows Server 2012 - Hyper-V
iTnews Academy: Microsoft Windows Server 2012 - Hyper-V
Interview: Australia's 'cloud-last' policy is dangerous.
Interview: Australia's 'cloud-last' policy is dangerous.
Interview: Vivek Kundra on Australia's 'cloud last' policy
Bankwest builds continuous delivery capability
Bankwest builds continuous delivery capability
To automatically deploy test/dev sandboxes by mid-year.
Veterans' Affairs sets sights on modernisation
Veterans' Affairs sets sights on modernisation
Data safe with Human Services, CIO says.
Citi Australia drops platform customisations
Citi Australia drops platform customisations
Technology chief shifts focus from building to leveraging systems.
VicRoads restructures IT team
VicRoads restructures IT team
Department moves to align with industry benchmarks.
Zurich Australia extends IT team offshore
Zurich Australia extends IT team offshore
Malaysian staff served from Australian data centres.
Leigh Berrell - Utilities CIO of the Year
Leigh Berrell - Utilities CIO of the Year
Yarra Valley Water CIO Leigh Berrell accepts his Benchmark Award for Utilities CIO of the Year.
Wayne McMahon - Retail CIO of the Year
Wayne McMahon - Retail CIO of the Year
Domino's Pizza CIO Wayne McMahon accepts his Benchmark Award for Retail CIO of the Year.
Inside Perpetual's ongoing IT transformation
Inside Perpetual's ongoing IT transformation
CIO Jenny Levy discusses how outsourcing will help the firm "simplify, refocus and grow".
Managing Complexity - Defence's Daniel McCabe
Managing Complexity - Defence's Daniel McCabe
Daniel McCabe, Assistant Secretary of Australia's Department of Defence, provides the audience at the iTnews Data Centre Strategy Summit with a deep dive into the organisation's data centre consolidation program.
How Facebook designed the data centre from scratch - Marco Magarelli
How Facebook designed the data centre from scratch - Marco Magarelli
The full keynote by Facebook data centre architect Marco Magarelli at the Australian Data Centre Strategy Summit. Magarelli details the design considerations behind the social network's Prineville, Oregon; North Carolina and Luleå, Sweden data centres.
Modernising Legacy Data Centres - Telstra's Jon Curry
Modernising Legacy Data Centres - Telstra's Jon Curry
Telstra general manager of managed data centres Jon Curry guides the audience at the iTnews Australian Data Centre Summit through the build of the telco's Clayton, Victoria data centre.
NSW Government launches NABERS data centre rating tools
NSW Government launches NABERS data centre rating tools
Matthew Clark from the NSW Department of Environment guides facilties managers through the details of the new NABERS data centre energy rating tool at the Australian Data Centre Strategy Summit.
NABERS launch panel: Australian Data Centre Strategy Summit
NABERS launch panel: Australian Data Centre Strategy Summit
Matthew Clark (NSW Dept of Environment), Greg Boorer (Canberra Data Centres), Glenn Allan (National Australia Bank), Mike Andrea (Strategic Directions) and Bob Sharon (Green Global Consulting) discuss the impact of the NABERS data centre rating.
Judges notes: Fortescue Metals [The Benchmark Awards]
Judges notes: Fortescue Metals [The Benchmark Awards]
iTnews' panel of judges discuss Fortescue Metals 'New World of Work" project, one of three shortlisted finalists for the Industrials category of the CIO Benchmark Awards.
Judges notes: Retail [The Benchmark Awards]
Judges notes: Retail [The Benchmark Awards]
iTnews' panel of judges discuss the shortlisted finalists for the Retail category of the CIO Benchmark Awards.
Judges notes: Pacific Aluminium [The Benchmark Awards]
Judges notes: Pacific Aluminium [The Benchmark Awards]
iTnews' panel of judges discuss Pacific Aluminium's lightning fast service desk refresh, one of three shortlisted finalists for the Industrials category of the CIO Benchmark Awards.
Judges notes: Domino's Pizza [The Benchmark Awards]
Judges notes: Domino's Pizza [The Benchmark Awards]
iTnews' panel of judges discuss Domino's Pizza's shift to hosted services, one of three shortlisted finalists for the Retail category of the CIO Benchmark Awards.
Judges notes: McDonald's Australia [The Benchmark Awards]
Judges notes: McDonald's Australia [The Benchmark Awards]
iTnews' panel of judges discuss McDonald's Australia's new self-service portal for employees, one of three shortlisted finalists for the Retail category of the CIO Benchmark Awards.
Latest Comments
Polls
Will you quit any cloud services in light of PRISM?

   |   View results
Yes
  60%
 
No
  40%
TOTAL VOTES: 65

Vote