iTnews
  • Home
  • News
  • Technology
  • Security

Auditors choose profits over security

By Darren Pauli
Jul 20 2011 11:27AM
Follow google news

Study reveals oversights in Aussie organisations.

A university study of more than 400 Australian organisations has found them exposed to intruders through network routers and switches left misconfigured and unpatched.

Auditors choose profits over security

Charles Sturt University teamed with penetration testers and security researchers for a three-year study of 1323 routers and 452 switches in organisations that handled credit cards and other sensitive information.

Researchers highligted gross oversights in security controls such as routers with default passwords, misconfigured network services and poor or absent access controls.

Only four percent of routers and 1.2 percent switches were patched and configured, they found.

It took organisations almost a year on average to patch switches; the devices were never tested by auditors who rarely examined the corresponding client software.

“Consequently, there is little incentive for the organisation under audit to maintain critical systems,” authors wrote.

Organisations had regular audits from “respectable” security firms and some were deemed compliant under the payment-card industry's data security standard and ISO 2700, a security-management standard.

But the industry's drive to the “lowest common denominator” meant organisations and auditors chose to overlook serious security flaws in the name of profits, said report author Craig Wright.

IT staff who had incentives tied to results would often “lie by omission” to pass the tests. And auditors would take their word rather than test and verify, which would treble the audit cost.

Auditors were "watchdogs and not bloodhounds", researchers wrote.

The risk from hacking left auditors “seeking the compliance tests that bring them the greatest returns with little risk of fallout when they fail”.

No auditor examined ther subjects' network-equipment firmware during the study and organisations were focused on getting the network auditor’s tick.

“It’s easier not to tackle the gaps and put a junior on the job,” Dr Wright said. “They know what needs to done to pass the audit and that’s what they focus on.”

Patch policy was present for servers and client operating systems but it took up to three months to fix server holes and 50 days to patch operating systems.

The policies were rarely required for network devices.

Operating system patches for client systems and firewalls were applied and tested within two months.

Wright scoffed at popular “tick-box” auditing arrangements, where networks were examined no more than every few months. Those arrangements were insufficient to ensure organisations were abreast of security vulnerabilities, he said.

“Spending money to demonstrate compliance does not in itself provide security.”

Government and commercial groups such as the Payment Card Industry were blamed in the report for inflating the importance of compliance schemes, company negligence rules and governance functions when reports to demonstrate compliance were used in place of a “real effort to ensure that data protection occurs”.

The focus of the legal system on “conventional, fault-based tort principles” (litigation) meant a favourable compliance report could absolve an organisation.

Audits should be done weekly and drill into a section of security, researchers wrote. Dr Wright said auditors big and small here and in Britain and the US were guilty.

He said the hallmark of a good auditor was integrity; they should be chosen based on a trial assessment of an organisation’s network and be instructed to test by information security frameworks such as OWASP that looked at web-application security.

“The practice of implementing monitoring controls that do not report on breaches but which do satisfy the compliance needs of an organisation can cost far more in the long term,” researchers concluded.

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.

Copyright © SC Magazine, Australia

Tags:
auditorsexploitsframeworkpatchingresearchrouterssecurityvulnerabilities

Related Articles

  • Apple bumps up security in fresh operating system releases Apple bumps up security in fresh operating system releases
  • Meta accuses NSO Group of violating court order by WhatsApp spear phishing Meta accuses NSO Group of violating court order by WhatsApp spear phishing
  • Researchers build self-replicating AI worm with BYO LLM Researchers build self-replicating AI worm with BYO LLM
  • Anthropic opens Claude Mythos Preview AI program to Australia Anthropic opens Claude Mythos Preview AI program to Australia
Join our WhatsApp Channel

Partner Content

Agile isn’t the problem: why projects still fail, and what’s missing
Partner Content Agile isn’t the problem: why projects still fail, and what’s missing
Take control of your connectivity with Telstra’s Adaptive Networks Centre
Partner Content Take control of your connectivity with Telstra’s Adaptive Networks Centre
Why resilient communications are becoming critical infrastructure for modern enterprise IT
Promoted Content Why resilient communications are becoming critical infrastructure for modern enterprise IT
Scalable AI solutions: secure delivery
Scalable AI solutions: secure delivery

Sponsored Whitepapers

Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
High-volume data sources for AI-driven security analytics
High-volume data sources for AI-driven security analytics
How healthcare organisations can get more value from cloud
How healthcare organisations can get more value from cloud
1 in 3 companies lose SaaS data. Here’s how to prevent it
1 in 3 companies lose SaaS data. Here’s how to prevent it

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
  • Security Exhibition & Conference Security Exhibition & Conference
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

Defence says Palantir is "sandboxed" in its environment

Defence says Palantir is "sandboxed" in its environment

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Microsoft backs down on legal threats against 0day disclosing researchers

Microsoft backs down on legal threats against 0day disclosing researchers

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.