Chapter 1 Page 2
The audit objective is to verify that access privileges are granted in a manner
AUDIT PROCEDURES
Review the organization’s policies for separating incompatible functions
descriptions and positions.
Review personnel records to determine whether privileged employees
undergo an adequately intensive security clearance check in
compliance with company policy.
Review the users permitted logon times. Permission should be
AUDIT OBJECTIVES RELATING TO PASSWORD POLICY
The audit objective here is to ensure that the organization has an adequate
AUDIT PROCEDURES
Verify that all users are required to have passwords.
Determine that procedures are in place to identify weak passwords.
Assess the adequacy of password standards such as length and
expiration interval.