No rude awakening in auditing
Vienna (pts029/17.04.2013/21:15) – Functioning and secure IT is not only important for the internal control system and proper financial statements, it is often the heart of many corporate divisions.
‚Relying solely on the auditor who identifies existing vulnerabilities and takes them into account in his risk assessment is certainly not enough,‘ says Peter Kopp, auditor and shareholder of CONSULTATIO (ht://www.consultatio.at ). „Not allowing serious weaknesses and defects to arise in the first place is far less risky and economically more favorable.“
How to avoid unnecessary risks? This was demonstrated by IT experts and CONSULTATIO cooperation partners Benjamin Böck and Gerd Brunner (http://www.xsec.at ) on 17 April at CONSULTATIO Steuerberatung und Wirtschaftsprüfung.
It does not help software update for human errors
“70 out of 100 employees plug a donated USB stick into the company network and risk corporate data being damaged or made accessible to unauthorized persons,” says Benjamin Böck from his consulting practice. The task of a commissioned security test was to check how employees react when USB sticks with malware fall into their hands as a supposed gift. “Technical and organizational vulnerabilities are increasingly being exploited in combination with human errors to obtain confidential information,” says Gerd Brunner. This is also known by hackers who are increasingly relying on human imprudence with targeted social engineering attacks.
„I want to go to the Suedszee 95%“ is a secure password
What are secure passwords and how do I choose them? While so far abbreviations have liked to be taken, so instead of „I want to go to the South Seas“, IwidS95, the latest trend is to use whole phrases. The password is longer than before and therefore offers significantly higher protection. They can be created in a simple way, are easy to remember and can be entered faster. By adding numbers and special characters as well as an intentional spelling error, the complexity can be increased even further, says Benjamin Böck.
But none of this is of any use if personal passwords are passed on to colleagues. „This makes it impossible to understand who has carried out which actions in a system,“ warns Benjamin Böck. „Many problems have also arisen from angry employees.“ Access rights of retired employees should be changed immediately.
Commissioned hacker attacks
The IT system, as an essential part of accounting, is usually subjected to a basic check in the audit and checked for certain risks. Discovered vulnerabilities and security holes are identified together with resulting risks and suggestions for improvement. „IT is too important for a company to be smart through damage.“ Better get tips from a professional beforehand!, says Peter Kopp.
Questionnaire:
Mag. Peter Kopp
CONSULTATIO Steuerberatung Wirtschaftsprüfung (ht://www.consultatio.at )
Phone +43 1 27775-252
Email: peter.kopp@consultatio.at
DI (FH) Gerd Brunner
XSEC infosec GmbH http://www.xsec.at )
Phone +43 1 27775-490
Email: gerd.brunner@consultatio.at
(End)
Foreign Office: CONSULTATIO Steuerberatung Wirtschaftsprüfung
Contact person: Mag. Isabella Wuthe, MAS
Tel: +43 1 27775-277
Email: isabella.wuthe@consultatio.at
Website: www.consultatio.at
[ Quelle: http://www.pressetext.com/news/20130417029 ]
