0% found this document useful (0 votes)
13 views16 pages

Networking Audit Program Overview

Uploaded by

Fares Salman
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
13 views16 pages

Networking Audit Program Overview

Uploaded by

Fares Salman
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Networking

AUDIT PROGRAM
&
INTERNAL CONTROL QUESTIONNAIRE
The Information Systems Audit and Control Association
With more than 23,000 members in over 100 countries, the Information Systems Audit and Control Association®
(ISACA™) is a recognized global leader in IT governance, control and assurance. Founded in 1969, ISACA
sponsors international conferences, administers the globally respected CISA® (Certified Information Systems
Auditor™) designation earned by more than 25,000 professionals worldwide, and develops globally applicable
information systems (IS) auditing and control standards. An affiliated foundation undertakes the leading-edge
research in support of the profession. The IT Governance Institute, established by the association and foundation
in 1998, is designed to be a "think tank" offering presentations at both ISACA and non-ISACA conferences,
publications and electronic resources for greater understanding of the roles and relationship between IT and
enterprise governance.

Purpose of These Audit Programs and Internal Control Questionnaires


One of the goals of ISACA’s Education Board is to ensure that educational products developed by ISACA support
member and industry information needs. Responding to member requests for useful audit programs, the Education
Board has recently released audit programs and internal control questionnaires on various topics for member use
through the member-only web site and K-NET. These products are intended to provide a basis for audit work.
E-business audit programs and internal control questionnaires were developed from material recently released in
ISACA’s e-Commerce Security Technical Reference Series. These technical reference guides were developed by
Deloitte & Touche and ISACA’s Research Board and are recommended for use with these audit programs and
internal control questionnaires.
Audit programs and internal questionnaires on other subjects were developed by ISACA volunteers and reviewed
and edited by the Education Board. The Education Board cautions users not to consider these audit programs and
internal control questionnaires to be all-inclusive or applicable to all organizations. They should be used as a starting
point to build upon based on an organization’s constraints, policies, practices and operational environment.

Disclaimer
The topics developed for these Audit Programs and Internal Control Questionnaires have been prepared for
the professional development of ISACA members and others in the IS Audit and Control community.
Although we trust that they will be useful for that purpose, ISACA cannot warrant that the use of this
material would be adequate to discharge the legal or professional liability of members in the conduct of their
practices.

September 2001

Networking
Audit Program and ICQ
Get Preliminary Procedure Step: Comments:
Information Network Diagram

Details/Test:
 Obtain a complete network diagram, including a copy of a hardware
configuration diagram including all connections to the network topology,
servers, communications gear, workstations, bridges, repeaters, protocol
converters etc.
- Ensure that the network diagram indicates how external parties access
the network and for what services.

Get Preliminary Procedure Step: Comments:


Information Other materials

Details/Test:
 Obtain and review the following:
- Policies, standards, and procedures
- Vendor and vendor rep name for ISP homepage
- Names of responsible persons for intranet content and administration
- Samples of monitoring reports for the firewall
- Samples of problem reporting forms and security violation reports
- Contingency plan
- A descriptive inventory listing for all hardware and software. For all
system software and utilities, include current version number and patch
history if applicable
- Any "service level agreements" with corporate telecommunications or
systems departments
- List of network services and equipment provided by external parties.
- List of devices which will open their own connection to the outside (i.e.
devices that will phone home if they start to have problems)
Networking
Audit Program and ICQ

Get Preliminary Procedure Step: Objective: Policy/Guidance:


Information Internal Control The objective of the ICQ This questionnaire to be
Questionnaire (ICQ) is to evaluate the overall completed by the
network security of network administrator
company. Data that are and/or the manager of
transmitted over the area.
network lines may be
subject to a variety of Comments:
exposures: disclosure,
errors, misrouted
messages, or third-party
negligence. To the
extent possible, we
should attempt to
recommend controls
that are primarily
preventive in nature. In
the absence of
preventive controls, we
should recommend
detective controls that
will act both as an audit
trail and as a deterrent.
Networking
Audit Program and ICQ

Details/Test:
GENERAL

 Are there documented procedures for using the network?


 Has the responsibility and liability of network vendors been defined (e.g.,
contracts)?
 Is there any inventory of data network equipment, including lines, terminals,
modems, controllers, etc.?
 Has a network diagram, which illustrates physical and logical connections between
network equipment, been prepared?
 Does network documentation include a description of:
- Data network equipment used to support each network applications?
- Protocols used?
- Gateways to other networks?
 Has networking equipment been labeled to facilitate cross-reference to
documentation?
 Are access codes periodically changed?
- How often?
 Are terminals physically or logically defined to the network based on written
authorization?
 Is there a system access policy to be followed by external parties?
 Is there an inventory of externally accessible applications and services?
 Is there documentation regarding which applications and information external
parties have access?

PERFORMANCE/INTEGRITY
 Is there a specific terminal designed to monitor activity within the on-line system?
 Have performance standards been established?
 Do priorities (by terminal or application requirements) assigned to each network line
seem reasonable?
 Do network support personnel review new applications to determine their impact on
existing systems?

Details/Test (continued):
 Does capacity planning include analyses of message length, protocol, transaction
volume, and message traffic?
 Are response times measured and evaluated for possible enhancement of network
throughput?
 Is hardware performance compared to vendor specifications?
 Does management routinely review vendor services performed?
 Are periodic checks of the network made to verify proper operation and detect
terminal/line/ modem errors?
 Are network hardware failures documented, including corrective actions taken?
 Have guidelines for network modem "wrap tests" been established? (Wrap tests are
run to determine whether errors are caused by modems, terminals, or controllers.)
 Are modem switch settings periodically compared to the network configuration line
specifications?
 If leased circuits are used, has line conditioning been considered to reduce
transmission errors?
 Has digital transmission been considered to reduce transmission errors?
 Have procedures been established to ensure that all transactions sent have been
received? (e.g., record counts sent/received)?
 Do we use a store and forward messaging system?
- If so, are there appropriate controls to ensure that transactions were sent to
their proper destinations?
 Is there a review of all transaction messages that are unaccounted for, distorted,
duplicated, or delayed?
 Does the on-line software log all errors and re-transmissions?
 Is an individual assigned to review error logs and notify the security personnel of
anything unusual?
 Is there a method for creating a journal (trail) of all messages sent?
 Does each message contain identifying information such as:
- Port number (if dialed)?
- Message number?
- Terminal?
- User?
- Date?
- Transaction Code?
- End-of-message?
- End-of-transmission?
 Is there a method (sequence number on each message) to account for all
messages and to identify illegal messages?
 Are there back-up facilities for the on-line system in the event of an emergency?
 Are dial-up lines used in case of leased line failures?
- If so, is there a sufficient number of dial-up lines (2 lines per modem) available
to facilitate the Switched Network Back-up Compatibility (SNBU)?
 Are there back-up modems available for these lines?
 In the event of service interruptions, are there written procedures to follow for
restarting the on-line network?
 Does the system provide for restart/recovery procedures to regain communication
following hardware/software failure?

DIAL-UP SECURITY

 Is there a list of authorized users of dial-up facilities?


 Have provisions been established to ensure the confidentiality of telephone
numbers (e.g., unlisted)?
 Are dial-up telephone numbers changed periodically?
 Are dial-up telephone numbers on a three-digit exchange that is different from the
company's main, published number?
 Are telephone numbers removed from modems to prevent access to the dial-in
telephone number?

Details/Test (continued):
 Is a "call-back" to a specific telephone number and re-verification of the user ID
required?
 Can the CPU interrogate a dial-up terminal, automatically obtain its ID, and verify
that the terminal calling is the same terminal that "says" it is calling?
 Does the system disconnect users who hang up the telephone without properly
logging off?
 Is dial-up access limited to only those telephone numbers controlled by the IS
department. (Dial-up should not be permitted to modems, which may be part of a
local desktop configuration since this may allow unauthorized users to connect to
the network without being properly authenticated.

PHYSICAL SECURITY

 Are physical and environmental concerns adequately addressed to protect network


equipment from adverse operating environments?
 Are network controllers located in a secure area under the control of operations
personnel or a central network facility?
 Are cables and video display screens electrically shielded to prevent electrical
emanations or physical tampering?
 Are cable/line closets locked and unlabeled?
 Are cables/lines periodically checked for active/passive wiretaps?
 Is access to test equipment (e.g., data scopes, line monitors) and diagnostic
network software restricted to appropriate personnel?
 Is test equipment used to monitor the network controlled?
 Is a data scope being used to monitor on-line circuits and equipment? If so:
- Is it in a secured area?
- Does it log entries?
- Has it the capability to enter data onto a line?
- Does the unit restrict access to authorized personnel only?
 Are logon, system commands, and on-line transaction documentation manuals
labeled as confidential and placed in a secured area when not in use?

LOGICAL SECURITY

 Are passwords and unique user codes required to logon to network software?
 Has the principle of least privilege (e.g., granting the minimum access authorization
necessary for performance required tasks) been implemented?
 Are only authorized personnel permitted to access network software?
- If so, who?
 Are only authorized personnel permitted to inspect storage buffers (e.g., using
NCCF software or data scopes, users can examine messages including IDs and
passwords)?
 If the network has been configured to allow remote terminal functions (e.g., vendor
maintenance or service) by non- IS personnel, are vendor field service default
parameters reviewed for demonstrated need?
 If a service bureau is being used to transmit data, has it provided adequate security
measures for Ids and password control?
 Does the system prevent the display of any "HELP" information before the user has
successfully logged on?
 During logon, does the system inform the user when he/she last logged off?
 Are terminal buffers erased after successful logon?
 Are users prevented from making an unlimited number of unsuccessful logon
attempts?
 If there are nonexistent terminals predefined in the system tables, are intruder
terminals prevented from being attached to the system as one of the predefined
entities?
 If sensitive information is being processed, are there adequate controls to ensure
that output can only be directed to "authorized" printers or "authorized" print
facilities?

Details/Test (continued):
 Has message encryption been considered as a means of securing sensitive
data and password during transmission?
 If encryption is being used, have controls over the encryption key been
developed?
 Does the system employ a method of traffic flow security to conceal the
presence of valid messages on the line by causing the circuit to appear
busy at all times or by encrypting the source and destination addresses of
valid messages?
 On systems with electronic mail capability where messages pop up in
interactive mode, have users been instructed to ignore an intruder's request
for an ID/password by being informed that this is not a legitimate system.
Networking
Audit Program and ICQ

Network Contingency Procedure Step: Comments:


Planning Backup Procedures
Details/Test:
 Review the backup materials.
- Determine if the backup and recovery procedures are being followed.
 Interview IS personnel to determine if they have been cross-trained.
- Review training records to determine the amount of cross training
provided.

Network Contingency Procedure Step: Comments:


Planning Disaster Recovery Plan
Details/Test:
 Obtain and review a copy of the disaster recovery plan and the alternate
site agreement, if any.
- Determine if they are complete and current, and if executive
management has signed off on the plan.
 Determine who was responsible in developing the plan and if users and all
facets of networking were adequately involved in its development.
 Determine if a risk assessment has been prepared and if it appears
reasonable.
 Determine if executive management has approved the funding for an
alternate site and the testing of the disaster recovery plan.
- Observe a test of the plan, if possible.
 Review the results of the test of the disaster recovery plan.
- Determine if corrective action has been taken on any problems incurred
during the test.
 Interview users and/or IT personnel to determine if they have been trained
in their responsibilities in case of a network emergency or disaster.
- Determine if they are aware of manual procedures that are to be used
when processing is delayed for an extended period.
 Ensure that the communications facilities are sufficient with respect to
capacity and redundancy.
 Ensure that the communications equipment at the backup site is consistent
with that at the current production site.
Internet Procedure Step: Comments:
Policy understanding and
review
Details/Test:
 Determine the extent and understanding of the Internet usage policy.
 Identify the process that was used to develop the policy.
- Ascertain whether the process considered the value of and degree of reliance
on the firewall and the severity, probability, and extent of the potential for direct
and indirect harm.
 Assess whether the policy:
- Identifies the specific assets that the firewall is intended to protect and the
objectives of that protection (integrity, availability, and confidentiality).
- Describes the organizational structure and associated responsibilities and
accountability of personnel who will be charged with implementing the policy,
monitoring compliance with the policy and adhering to the policy.
- Supports the legitimate use and flow of data and information.
- Documents what information passing through the firewall will be monitored
(limit organizational liability, reduce abuse, support prosecution for abuse).
- Is consistent both in tone and in principle with other organizational policies and
accepted practice (e.g. availability of Internet access for non-business use).
 Ascertain whether legal counsel has reviewed the policy to ensure consistency with
requirements and limitations imposed externally (laws, regulations etc.).
 Determine whether management approval of the policy has been sought and
granted and the date of the most recent review of the policy by management.
 Identify how the Internet policy was/is communicated to users and how awareness
is maintained. Select a sample of users and discuss their understanding of their
responsibilities related to Internet use and how to report problems.
 Determine whether standards and procedures have been defined to specify the
means by which the policy is implemented.
 Assess whether the standards and procedures specify who is responsible and
empowered to do each function required for the proper operation of the firewall.
 Assess whether the security policy:
- Is easy to read and locate relevant sections
- Is versioned and dated
- Is carefully worded with all ambiguous terms precisely defined
- Sets out acceptable conditions of use as well as unacceptable conditions of use
- Is widely communicated to affected persons
- Is reviewed at regular intervals
 Consider whether the following issues are addressed in the policy document:
- Scope of the policy in relation to other internal and external networks with which
it may be connected.
- Basic philosophy that may be used for making non-deterministic decisions.
- Governing policies, laws, contractual terms and conditions, or other policies
internal to the Company.
- Identification of the person who has ultimate authority to interpret and apply the
policy to a particular situation.
- Allowance for the policy to be temporarily waived by a person of authority under
certain conditions or guidelines.
- Formal definition of how the people affected by the policy will be informed of its
contents.
- Frequency and necessity for reviews of the policy.
- Outline of the assets that must be protected, and from what threats
- Security incident handling principles.
- Guidelines for liability of personnel with regard to security breaches to
discourage people from hiding details of a breach that they may have
(somewhat innocently) been involved in.
- Guidelines regarding investigation of incidents and courses of action that could
be taken by decision-makers based upon details of the security breach,
including referral to law enforcement agencies, as well as internal investigation
and disciplinary principles.

Details/Test (continued):
 Consider whether the rights and responsibilities of users are addressed in the policy
document, including:
- Account use, by both the account holder and the resource provider. Special
conditions may apply to the use of normal user accounts, and public access
accounts (like anonymous ftp), and these conditions could be expressed here.
- Software and data access and use, including sources of data and software.
- Disclosure of information, which is potentially harmful, such as password
information or configuration information.
- Etiquette, including acceptable forms of expression (e.g. non-offensive
expression expected for unsolicited electronic mail), and unacceptable
practices (such as the forging of electronic mail and news articles).
- Password uses and formats.
- Rights to privacy, and the circumstances under which the resource provider
may intrude on the files held under or activities practiced by an account.
- Other miscellaneous guidelines regarding reasonable practices, such as the
use of CPU cycles and temporary general access storage areas. Copyright
issues may also be discussed here.
 Consider whether the rights and responsibilities of resource providers are
addressed in the policy document, including:
- Physical security guidelines.
- Privacy guidelines.
- Configuration guidelines including:
- Allocation of responsibility
- Network connection guidelines
- Authentication guidelines
- Authority to hold and grant account guidelines
- Auditing and monitoring guidelines
- Password format, enforcement and lifetime guidelines
- Login banners.

Internet Procedure Step: Comments:


Hardware configuration
Details/Test:
 Determine and map the Internet hardware configuration.
- Ensure the adequacy of firewall construction.

Internet Procedure Step: Comments:


CERT Advisories
Details/Test:
 Determine if and who is keeping current on CERT (Computer Emergency
Response Team) and other advisories.

Internet Procedure Step: Comments:


Host security health
Details/Test:
 Determine the extent and frequency of monitoring of the host's security
health.
Internet Procedure Step: Comments:
Network activity monitoring
Details/Test:
 Determine the extent and regularity of monitoring of network activity.

Internet Procedure Step: Comments:


Intrusion Detection
Details/Test:
 Determine the extent the intrusion detection monitoring of network activity.

Internet Procedure Step: Comments:


Router general security
Details/Test:
 Determine if routers are protected by secure authentication and access
control.
 Review that all routers use multiple levels or tiers to ensure individuals have
pre-assigned rights, as appropriate.
- Ensure that only one or two people have access to configure and
update the network.
- Ensure adequate protection of address configurations and routing
tables, determine that passwords are, at a minimum, ten alphanumeric
characters.
- Ensure that router modifications are done in a secure and controlled
fashion.

Internet Procedure Step: Comments:


Router management
Details/Test:
 Determine if the more secure out-of-band router management is used. In-
band management allows router configurations over the network rather than
via physical access and system code knowledge. As a compromise, in-
band updates should be through a dial-up port with dial-back security.

Internet Procedure Step: Comments:


Router physical security
Details/Test:
 Ensure that the routers are physically secure.

Internet Procedure Step: Comments:


Router configuration
security
Details/Test:
 Ensure that router configuration file information is encrypted, particularly
passwords. Data compression for efficiency may address this need.

Internet Procedure Step: Comments:


Router activity review
Details/Test:
 Determine the extent and review of router activity.
- Especially important is an audit trail of all attempts to access the router,
view its configurations, and change its settings.
- Determine the use of notification--the NOS polling routers and notifying
administrators when there is an erroneous login.

Internet Procedure Step: Comments:


Router change testing
Details/Test:
Determine the extent of testing when changes occur.

Internet Procedure Step: Comments:


Router change procedures
Details/Test:
 Determine procedures for updating router rights and passwords, especially
when employees are hired, leave, or change responsibilities.

Internet Procedure Step: Comments:


Router password
management
Details/Test:
 Determine if back-door access passwords are used and how router
password management occurs.

Networking
Audit Program and ICQ

Internet Procedure Step: Comments:


E-mail binary attachments
Details/Test:
 Determine if binary file attachments are allowed. This is an easy way to
bring a virus into the network on the back of e-mail.

Internet Procedure Step: Comments:


Router gateway
Details/Test:
 Determine if at least one router is an access gateway with router
capabilities. By having this, there is, at least, a warning of an attachment
attempt.

Internet Procedure Step: Comments:


Unauthorized log-on
attempts
Details/Test:
 Determine if unauthorized log-on attempts are recorded, alarmed, and sent
into a black hole.

Intranet Procedure Step: Comments:


Appropriate content
Details/Test:
 Obtain access to the Intranet and review all site information and links for
appropriateness.

Intranet Procedure Step: Comments:


Site page security

Details/Test:
 Review the security to site pages.
- Update access should reside with the owners only. Security should be
such to allow no access from the outside for any page, including those
responsible for maintenance. Maintenance should occur on-site only.

Intranet Procedure Step: Comments:


Additional information

Details/Test:
 Determine if additional information and uses could be added to the site.

Networking
Audit Program and ICQ
Physical Controls Procedure Step: Comments:
Server security
Details/Test:
 Verify the physical security provided for servers and configurable
communications/networking equipment is adequate.
- Verify that all servers are secured in an area inaccessible to all but
authorized personnel.
- Determine how access authorized, controlled, and monitored.
- Verify that unrelated equipment and supplies are not stored in the
secured area.

Physical Controls Procedure Step: Comments:


LAN distribution security
Details/Test:
 Verify the physical security provided for LAN distribution equipment is
adequate.
- Verify that all major, primary distribution equipment is in controlled
access areas.
- For secondary distribution equipment (small clusters), determine that
equipment is properly protected from accidental disconnection or
disturbance.

Physical Controls Procedure Step: Comments:


Physical workstation
security
Details/Test:
 Determine if physical workstation security is appropriate and adequate.

Physical Controls Procedure Step: Comments:


Environmental controls
Details/Test:
 Determine if environmental conditions meet equipment specifications
including:
- Electrical supplies, including UPS and emergency power and
conditioning equipment
- HVAC systems and controls
- Static control

Physical Controls Procedure Step: Comments:


On-site storage of data
Details/Test:
 Determine if onsite storage of all system media is adequate to prevent
unauthorized access.

Networking
Audit Program and ICQ
Employee Education Procedure Step: Comments:
Amount of education on
policies
Details/Test:
 Determine the amount of employee education as to corporate networking
policies and procedures.
 Determine the education level of employees in the efficient use of hardware
and software.

Employee Education Procedure Step: Comments:


Security awareness
Details/Test:
 Determine the level of security awareness of employees who use networks,
including vulnerabilities, methods of control, and conditions of copyright
laws regarding use and duplication.

Employee Education Procedure Step: Comments:


Disciplinary actions
Details/Test:
Determine if disciplinary actions have been formulated for breeches of company
data security guidelines.

Firewall security Procedure Step: Comments:


Firewall vendor
Details/Test:
Review firewall vendor information to determine the level of trust that can be
expected from the firewall.

Firewall security Procedure Step: Comments:


Firewall design
Details/Test:
 Examine the firewall design.
Determine it's known security problems. These problems can be located in all
kind of places and therefore the search will be extremely time consuming. As an
example, look how the firewall is handling buffers and buffer overflows.

Firewall security Procedure Step: Comments:


Firewall log review
Details/Test:
 Examine firewall logs.
- Turn on detailed logging for a selected period and examine the logs in
detail. This may take quite some time but we will get a sense of
whether or not the firewall is working properly. In addition, logs will also
be created if a service is used which we did not know was enabled or
being used on the system. By examining the logs, this can be detected
and corrected.

Networking
Audit Program and ICQ
Firewall security Procedure Step: Comments:
Firewall testing
Details/Test:
 Determine and perform firewall testing. The objective is to attempt to
penetrate the firewall as well as to bypass it. Technical problems such as
known vulnerabilities as well as misconfiguration and badly implemented
security policies are exploited, if possible.
Create a test plan.

Firewall security Procedure Step: Comments:


Firewall exposures
Details/Test:
 Download and run any or all of the following security products against the
firewall:
- ISS
- SATAN
- TRIPWIRE,
- COPS.
 Evaluate the results for exposure and vulnerabilities.
Before attempting this against any production system it is best to test
against a test system. The IS department should be aware that any
testing of this type is going on since it is possible to cause the system to
crash.

E-mail security Procedure Step: Comments:


Level of security
Details/Test:
 Determine the level of security over stored and transmitted e-mail
messages.
Gain an understanding of any security available within the e-mail system.

E-mail security Procedure Step: Comments:


Policy review
Details/Test:
Gain an understanding of e-mail security through the formal security policy. The
policy should provide a clear standard that describes the reasons and
objectives for security; the need to protect corporate data; who is responsible
for maintaining security; the level of confidentiality, integrity, and availability
desired; clearly acceptable uses for the e-mail system; and, any cautions
regarding monitoring.

E-mail security Procedure Step: Comments:


Monitoring
Details/Test:
 Determine the extent of monitoring for e-mail traffic.

E-mail security Procedure Step: Comments:


Backup practices
Details/Test:
 Determine and analyze the backup practices for e-mail messages.

You might also like