0% found this document useful (0 votes)
11 views2 pages

Virus Detection Audit Program Guide

Uploaded by

Fares Salman
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
11 views2 pages

Virus Detection Audit Program Guide

Uploaded by

Fares Salman
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Contributed 6/9/99 by Matthew M.

Dudkowski
<[Link]@[Link]> Virus Detection Audit
Program Prepared By ___ Date____________ Engagement
Team Name Initials I. Planning 1. Schedule an
opening meeting with the appropriate MIS management
for the area under audit to discuss the scope and
approach for the audit. 2. Prepare an audit program
and time budget. 3. Review the scope and audit
program with management prior to beginning field
work. II. Anti-virus Software 1. Obtain corporate
anti-virus policy. This should identify the
following: a) Policy definition and dissemination
b) Education for end users on how to use the
software c) Education and training of network
administrators and help desk personnel d)
Procedures end-users must take when a virus is
detected 2. Obtain an understanding of the current
network architecture and design by acquiring a copy
of the network map for all locations. Identify all
network resources where computer viruses could
potentially enter the Client Intranet either
internally or via the Internet. This include the
following: a) e-mail attachments from within and
outside of the company b) employees bringing in an
infected diskette from home c) employees bringing
in shrink wrapped software from a vendor that has
been infected at the factory. d) contractors
bringing in infected disks from the outside
Evaluate whether networks are vulnerable to
computer viruses, worms, or other kinds of security
threats. 3. Select a sample of internal PCs and
validate that anti-virus protection software is
installed at the desktop level. Verify that the PC
is running the latest version of the anti-virus
protection software. 4. Select a sample of internal
PCs and run the anti-virus protection software
noting if any PCs have infected files. 5. Select a
number of public network drives and run the anti-
virus detection software noting if any network
servers have infected files. 6. Obtain an
understanding of the UNIX environment, specifically
in regards to storage of files for the PC
environment. a) inquire as to the procedures of
scanning files for viruses which are stored on UNIX
servers 7. Evaluate security concerning the Windows
NT Viruswall server a) Choose File Manager then
select Disk Administrator to make sure the server
is using NTFS as its file allocation scheme. If it
uses FAT in any disk partition, it is not secured.
b) Check built in accounts (Administrator etc.)
Review policies (length of passwords, expiration
period, etc.) Review built in group memberships
(Dumpall utility) Review rights for all accounts.
c) Check "users" rights and permissions. (use the
Dumpall utility). d) Evaluate security features of
the antivirus application residing on the Viruswall
server. e) Determine which services are running on
the NT server. f) Determine if the most current
version of the virus signatures are loaded on the
VirusWall.

Common questions

Powered by AI

User education is essential as it empowers end users to use the anti-virus software correctly, recognize signs of infection, and follow established procedures when a virus is detected. This contributes significantly to the overall effectiveness of an organization's virus protection strategy .

Organizations should identify all network resources where computer viruses could potentially enter, such as through email attachments, infected diskettes, or external devices. They should evaluate network architecture and identify potential entry points for viruses or worms, ensuring robust defenses are in place .

Understanding UNIX scanning procedures is important in a mixed OS network because it ensures comprehensive protection against viruses across all systems. Each OS might present unique vulnerabilities, and proper integration of scanning procedures helps create a cohesive security strategy .

To secure a Windows NT Viruswall server, ensure it uses NTFS as its file allocation scheme, review built-in account policies, check user rights and permissions using tools like Dumpall, and evaluate the security features of the antivirus application on the server. Additionally, check that the most current virus signatures are loaded .

The corporate anti-virus policy should include policy definition and dissemination, education for end users on how to use the software, education and training of network administrators and help desk personnel, and procedures that end-users must take when a virus is detected .

Public network drives are a risk for virus spread as they can host infected files that might be accessed by multiple users. Mitigation involves running anti-virus detection regularly on these drives to identify and isolate infected files, and implementing strict access controls .

Having the latest virus signatures on the VirusWall server is critical as it ensures the server can recognize and block the latest threats. Without updated signatures, the server may not detect new viruses, leaving the network vulnerable to infections .

A network map is crucial for visualizing all the physical and logical components of the network, which helps identify potential entry points for computer viruses. It allows IT teams to strategically place protective measures, evaluate network vulnerabilities, and plan effective virus response protocols .

The file allocation scheme impacts security because NTFS includes security features like file permissions and encryption, while FAT does not. Using NTFS ensures a higher level of data protection and security on the VirusWall server, reducing the risk of unauthorized access or infection .

The steps include selecting a sample of internal PCs to validate that anti-virus protection software is installed, verifying that the latest version of anti-virus protection software is running, and running the anti-virus software to check if any PCs have infected files .

You might also like