Most of the best ideas in IT security – indeed, security in general – have been around for a long time. One that is all too often forgotten is the concept of “least privilege”, or using the bare minimum level of access to get the job done.
Quality-assurance audits are a bit like visits to the dentist; you know you need them, and that they will do you good, but that doesn't make the day itself any more fun. A recent audit I was involved in brought with it the usual flurry of activity to close off outstanding actions and generate the relevant reports.