<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IT SECURITY / AUDITOR DATA GATHERING AND AUDITING TOOLS in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/IT-SECURITY-AUDITOR-DATA-GATHERING-AND-AUDITING-TOOLS/m-p/19266#M895</link>
    <description>&amp;gt; Stew141 (Viewer) posted a new topic in Tech Talk on 02-20-2019 10:16 AM in the&lt;BR /&gt;&lt;BR /&gt;&amp;gt; Hi everyone, I am a long time&amp;nbsp; IT Auditor / Security Pro.&amp;nbsp; Over the years I've&lt;BR /&gt;&amp;gt; seen various struggles with conducting core IT audit tasks such as gathering and&lt;BR /&gt;&amp;gt; reviewing AD users and group information, and various teams ability to conduct&lt;BR /&gt;&amp;gt; meaningful IT Audits of technical subjects with limited resources/skill sets.&amp;nbsp;&lt;BR /&gt;&amp;gt; (I also see this as an issue within IT Security departments) So, I've decided&lt;BR /&gt;&amp;gt; to do something about it.&amp;nbsp; I'm developing a set of IT Audit Tools designed&lt;BR /&gt;&amp;gt; specifically for Auditors/Consultants to be able to gather technical information&lt;BR /&gt;&amp;gt; and produce audit reports.&amp;nbsp; The goal is to allow anyone to be able to conduct a&lt;BR /&gt;&amp;gt; technical assessment and have meaningful findings/recommendations without having&lt;BR /&gt;&amp;gt; to be a super geek or expert in every IT area.&lt;BR /&gt;&lt;BR /&gt;Laudable goal and intent, but be careful. I'm old enough to remember SATAN [1]&lt;BR /&gt;(eventually renamed SANTA, in a vain attempt to tamp down the outrage) and&lt;BR /&gt;the furor that erupted over it. It was basically the same idea ...&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;[1] - Security Administrators Tool for Analysing Networks, not that anyone ever&lt;BR /&gt;paid attention to the expansion ...&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org&lt;BR /&gt;Son of man, prophesy against the shepherds of Israel; prophesy&lt;BR /&gt;and say to them: 'This is what the Sovereign Lord says: Woe to&lt;BR /&gt;the shepherds of Israel who only take care of themselves! Should&lt;BR /&gt;not shepherds take care of the flock?' - Ezekiel 34:2&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt;</description>
    <pubDate>Wed, 20 Feb 2019 20:26:35 GMT</pubDate>
    <dc:creator>rslade</dc:creator>
    <dc:date>2019-02-20T20:26:35Z</dc:date>
    <item>
      <title>IT SECURITY / AUDITOR DATA GATHERING AND AUDITING TOOLS</title>
      <link>https://community.isc2.org/t5/Tech-Talk/IT-SECURITY-AUDITOR-DATA-GATHERING-AND-AUDITING-TOOLS/m-p/19255#M893</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi everyone, I am a long time&amp;nbsp; IT Auditor / Security Pro.&amp;nbsp; Over the years I've seen various struggles with conducting core IT audit tasks such as gathering and reviewing AD users and group information, and various teams ability to conduct meaningful IT Audits of technical subjects with limited resources/skill sets.&amp;nbsp; (I also see this as an issue within IT Security departments)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;So, I've decided to do something about it.&amp;nbsp; I'm developing a set of IT Audit Tools designed specifically for Auditors/Consultants to be able to gather technical information and produce audit reports.&amp;nbsp; The goal is to allow anyone to be able to conduct a technical assessment and have meaningful findings/recommendations without having to be a super geek or expert in every IT area.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I'd love to get your feedback on my tools and gauge the potential demand for these products.&amp;nbsp; Please check out my website and send me some feedback.&amp;nbsp; I would be eternally grateful!&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="https://blackboxauditor.com/" target="_blank"&gt;https://blackboxauditor.com&amp;nbsp;&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;-Stewart, CISA, CISSP, QSA&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Feb 2019 15:16:18 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/IT-SECURITY-AUDITOR-DATA-GATHERING-AND-AUDITING-TOOLS/m-p/19255#M893</guid>
      <dc:creator>Stew141</dc:creator>
      <dc:date>2019-02-20T15:16:18Z</dc:date>
    </item>
    <item>
      <title>Re: IT SECURITY / AUDITOR DATA GATHERING AND AUDITING TOOLS</title>
      <link>https://community.isc2.org/t5/Tech-Talk/IT-SECURITY-AUDITOR-DATA-GATHERING-AND-AUDITING-TOOLS/m-p/19259#M894</link>
      <description>&lt;P&gt;I went there and message said you caught us before ready. Can't really help.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Feb 2019 17:38:03 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/IT-SECURITY-AUDITOR-DATA-GATHERING-AND-AUDITING-TOOLS/m-p/19259#M894</guid>
      <dc:creator>smeek</dc:creator>
      <dc:date>2019-02-20T17:38:03Z</dc:date>
    </item>
    <item>
      <title>Re: IT SECURITY / AUDITOR DATA GATHERING AND AUDITING TOOLS</title>
      <link>https://community.isc2.org/t5/Tech-Talk/IT-SECURITY-AUDITOR-DATA-GATHERING-AND-AUDITING-TOOLS/m-p/19266#M895</link>
      <description>&amp;gt; Stew141 (Viewer) posted a new topic in Tech Talk on 02-20-2019 10:16 AM in the&lt;BR /&gt;&lt;BR /&gt;&amp;gt; Hi everyone, I am a long time&amp;nbsp; IT Auditor / Security Pro.&amp;nbsp; Over the years I've&lt;BR /&gt;&amp;gt; seen various struggles with conducting core IT audit tasks such as gathering and&lt;BR /&gt;&amp;gt; reviewing AD users and group information, and various teams ability to conduct&lt;BR /&gt;&amp;gt; meaningful IT Audits of technical subjects with limited resources/skill sets.&amp;nbsp;&lt;BR /&gt;&amp;gt; (I also see this as an issue within IT Security departments) So, I've decided&lt;BR /&gt;&amp;gt; to do something about it.&amp;nbsp; I'm developing a set of IT Audit Tools designed&lt;BR /&gt;&amp;gt; specifically for Auditors/Consultants to be able to gather technical information&lt;BR /&gt;&amp;gt; and produce audit reports.&amp;nbsp; The goal is to allow anyone to be able to conduct a&lt;BR /&gt;&amp;gt; technical assessment and have meaningful findings/recommendations without having&lt;BR /&gt;&amp;gt; to be a super geek or expert in every IT area.&lt;BR /&gt;&lt;BR /&gt;Laudable goal and intent, but be careful. I'm old enough to remember SATAN [1]&lt;BR /&gt;(eventually renamed SANTA, in a vain attempt to tamp down the outrage) and&lt;BR /&gt;the furor that erupted over it. It was basically the same idea ...&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;[1] - Security Administrators Tool for Analysing Networks, not that anyone ever&lt;BR /&gt;paid attention to the expansion ...&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org&lt;BR /&gt;Son of man, prophesy against the shepherds of Israel; prophesy&lt;BR /&gt;and say to them: 'This is what the Sovereign Lord says: Woe to&lt;BR /&gt;the shepherds of Israel who only take care of themselves! Should&lt;BR /&gt;not shepherds take care of the flock?' - Ezekiel 34:2&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt;</description>
      <pubDate>Wed, 20 Feb 2019 20:26:35 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/IT-SECURITY-AUDITOR-DATA-GATHERING-AND-AUDITING-TOOLS/m-p/19266#M895</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-02-20T20:26:35Z</dc:date>
    </item>
    <item>
      <title>Re: IT SECURITY / AUDITOR DATA GATHERING AND AUDITING TOOLS</title>
      <link>https://community.isc2.org/t5/Tech-Talk/IT-SECURITY-AUDITOR-DATA-GATHERING-AND-AUDITING-TOOLS/m-p/19338#M899</link>
      <description>&lt;P&gt;Anybody else have feedback on the site?&amp;nbsp; &lt;A href="https://blackboxauditor.com" target="_blank" rel="noopener"&gt;https://blackboxauditor.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 16:01:11 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/IT-SECURITY-AUDITOR-DATA-GATHERING-AND-AUDITING-TOOLS/m-p/19338#M899</guid>
      <dc:creator>Stew141</dc:creator>
      <dc:date>2019-02-22T16:01:11Z</dc:date>
    </item>
  </channel>
</rss>

