<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Kreslavsky IT blog &#187; Sox</title>
	<atom:link href="http://www.kreslavsky.com/tag/sox/feed" rel="self" type="application/rss+xml" />
	<link>http://www.kreslavsky.com</link>
	<description>News, guides, and tips to antivirus programmes, scripts, and security</description>
	<lastBuildDate>Sun, 29 Jan 2012 04:57:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Reports required as part of the IT Audit process</title>
		<link>http://www.kreslavsky.com/2008/12/reports-required-as-part-of-the-it-audit-process.html</link>
		<comments>http://www.kreslavsky.com/2008/12/reports-required-as-part-of-the-it-audit-process.html#comments</comments>
		<pubDate>Fri, 05 Dec 2008 00:13:33 +0000</pubDate>
		<dc:creator>Gil Kreslavsky</dc:creator>
				<category><![CDATA[Sox]]></category>
		<category><![CDATA[Aging]]></category>
		<category><![CDATA[Amp]]></category>
		<category><![CDATA[Auditing]]></category>
		<category><![CDATA[Change Logs]]></category>
		<category><![CDATA[Ntfs Permissions]]></category>
		<category><![CDATA[Remote Access]]></category>
		<category><![CDATA[System Privileges]]></category>

		<guid isPermaLink="false">http://www.kreslavsky.com/?p=449</guid>
		<description><![CDATA[Tweet Password Aging User Privileges System Privileges Remote Access Consolidated Change Logs NTFS Permissions Role Permissions &#38; Membership User Access Auditing Enabled]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.kreslavsky.com%2F2008%2F12%2Freports-required-as-part-of-the-it-audit-process.html&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://www.kreslavsky.com/2008/12/reports-required-as-part-of-the-it-audit-process.html"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.kreslavsky.com/2008/12/reports-required-as-part-of-the-it-audit-process.html"  data-text="Reports required as part of the IT Audit process" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://www.kreslavsky.com/2008/12/reports-required-as-part-of-the-it-audit-process.html" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://www.kreslavsky.com/2008/12/reports-required-as-part-of-the-it-audit-process.html"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><ul>
<li>Password Aging</li>
</ul>
<ul>
<li>User Privileges</li>
</ul>
<ul>
<li>System Privileges</li>
</ul>
<ul>
<li>Remote Access</li>
</ul>
<ul>
<li>Consolidated Change Logs</li>
</ul>
<ul>
<li>NTFS Permissions</li>
</ul>
<ul>
<li>Role Permissions &amp; Membership</li>
</ul>
<ul>
<li>User Access</li>
</ul>
<ul>
<li>Auditing Enabled</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.kreslavsky.com/2008/12/reports-required-as-part-of-the-it-audit-process.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Job Roles and Responsibilities &#8211; SOX Audit</title>
		<link>http://www.kreslavsky.com/2008/12/job-roles-and-responsibilities-sox-audit.html</link>
		<comments>http://www.kreslavsky.com/2008/12/job-roles-and-responsibilities-sox-audit.html#comments</comments>
		<pubDate>Fri, 05 Dec 2008 00:09:21 +0000</pubDate>
		<dc:creator>Gil Kreslavsky</dc:creator>
				<category><![CDATA[Sox]]></category>
		<category><![CDATA[Accountabilities]]></category>
		<category><![CDATA[Audit]]></category>
		<category><![CDATA[Auditing]]></category>
		<category><![CDATA[Business Process]]></category>
		<category><![CDATA[Business Threats]]></category>
		<category><![CDATA[Business Unit]]></category>
		<category><![CDATA[Continuity]]></category>
		<category><![CDATA[Establishing Security]]></category>
		<category><![CDATA[Experience Knowledge]]></category>
		<category><![CDATA[Feedback Systems]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Managing Director]]></category>
		<category><![CDATA[Mandate]]></category>
		<category><![CDATA[Metrics]]></category>
		<category><![CDATA[Necessary Resources]]></category>
		<category><![CDATA[Profitability]]></category>
		<category><![CDATA[Roles And Responsibilities]]></category>
		<category><![CDATA[Security Failures]]></category>
		<category><![CDATA[Security Strategy]]></category>
		<category><![CDATA[Senior Management]]></category>
		<category><![CDATA[Top Management]]></category>

		<guid isPermaLink="false">http://www.kreslavsky.com/?p=447</guid>
		<description><![CDATA[Tweet Depending on the size of an organization, responsibility may be divided into the following defined roles. It is important that responsibility is apparent and is supported by management. To achieve this, the accountable persons must actually assume their accountabilities (i.e. they have powers necessary to make corresponding decisions and the experience/knowledge to make the right decisions). Management and Human Resources should ensure that the necessary roles are correctly implemented. Board and Executives The Board of Directors and the managing director or CEO (or equivalent) are ultimately responsible for security strategy and must make the necessary resources available to combat business threats. This group is ultimately responsible for disseminating strategy and establishing security-aware customs within the organization. They have the mandate to protect and insure for continuity of the corporation and to protect and insure for profitability of the corporation. Information Security plays a crucial role in both of these aspects of senior management’s roles. Business process / data / operation owner This person is directly responsible for a particular process or business unit’s data and reports directly to top management. He/she analyzes the impact of security failures and specifies classification and guidelines/processes to ensure the security of the data for which he/she is responsible. There should not be any influence on auditing. Process Owner The process owner is responsible for the process design, not for the performance of the process itself. The process owner is additionally responsible for the metrics linked to the process feedback systems, the documentation of the process, and the education of the process performers in its structure and performance. The process owner is accountable for sustaining the development of the process and for identifying opportunities to improve the process. The process owner is the individual ultimately accountable for improving a process. IT Security manager/director This person is responsible for the overall security within the organization. The IT security manager(s) defines IT security guidelines together with the process owner. He/she is also responsible for security awareness and advising management correctly on security issues. He/she may also carry out risk analyses. It is important that this person be up-to-date on the latest security problems/risks/ solutions. Coordination with partner companies, security organizations, and industry groups is also important. System supplier The system supplier installs and maintains systems. A service level agreement should exist defining the customer/supplier roles and responsibilities. The supplier may be, for example, an external contracting company or the internal datacenter or System/Security administrator. This person is responsible for the correct use of security mechanisms. System designer The persons who develop a system have a key role in ensuring that a system can be used securely. New development projects must consider security requirements at an early stage. Project Leaders These people ensure that Security guidelines are adhered to in projects. Line Managers These managers ensure that their personnel are fully aware of security policies and do not provide objectives that conflict with policy. He/she enforces policy and checks actual progress. Users Users, or “information processors/operators,” are [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.kreslavsky.com%2F2008%2F12%2Fjob-roles-and-responsibilities-sox-audit.html&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://www.kreslavsky.com/2008/12/job-roles-and-responsibilities-sox-audit.html"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.kreslavsky.com/2008/12/job-roles-and-responsibilities-sox-audit.html"  data-text="Job Roles and Responsibilities &#8211; SOX Audit" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://www.kreslavsky.com/2008/12/job-roles-and-responsibilities-sox-audit.html" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://www.kreslavsky.com/2008/12/job-roles-and-responsibilities-sox-audit.html"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p>Depending on the size of an organization, responsibility may be divided into the following defined<br />
roles. It is important that responsibility is apparent and is supported by management. To achieve<br />
this, the accountable persons must actually assume their accountabilities (i.e. they have powers<br />
necessary to make corresponding decisions and the experience/knowledge to make the right<br />
decisions).<br />
Management and Human Resources should ensure that the necessary roles are correctly<br />
implemented.</p>
<ul>
<li><strong>Board and Executives </strong>The Board of Directors and the managing director or CEO<br />
(or equivalent) are ultimately responsible for security strategy and must make the necessary<br />
resources available to combat business threats. This group is ultimately responsible for<br />
disseminating strategy and establishing security-aware customs within the organization.<br />
They have the mandate to protect and insure for continuity of the corporation and to<br />
protect and insure for profitability of the corporation. Information Security plays a crucial<br />
role in both of these aspects of senior management’s roles.</li>
<li><strong>Business process / data / operation owner</strong> This person is directly responsible for a<br />
particular process or business unit’s data and reports directly to top management. He/she<br />
analyzes the impact of security failures and specifies classification and guidelines/processes<br />
to ensure the security of the data for which he/she is responsible. There should not be any<br />
influence on auditing.</li>
<li><strong>Process Owner</strong> The process owner is responsible for the process design, not for the<br />
performance of the process itself. The process owner is additionally responsible for the<br />
metrics linked to the process feedback systems, the documentation of the process, and the<br />
education of the process performers in its structure and performance. The process owner is<br />
accountable for sustaining the development of the process and for identifying opportunities<br />
to improve the process. The process owner is the individual ultimately accountable for<br />
improving a process.</li>
<li><strong>IT Security manager/director</strong> This person is responsible for the overall security<br />
within the organization. The IT security manager(s) defines IT security guidelines<br />
together with the process owner. He/she is also responsible for security awareness and<br />
advising management correctly on security issues. He/she may also carry out risk analyses.<br />
It is important that this person be up-to-date on the latest security problems/risks/<br />
solutions. Coordination with partner companies, security organizations, and industry<br />
groups is also important.</li>
<li><strong><span style="color: #888888;">System supplier </span></strong>The system supplier installs and maintains systems. A service level<br />
agreement should exist defining the customer/supplier roles and responsibilities. The<br />
supplier may be, for example, an external contracting company or the internal datacenter<br />
or System/Security administrator. This person is responsible for the correct use of security<br />
mechanisms.</li>
<li><strong>System designer</strong> The persons who develop a system have a key role in ensuring that<br />
a system can be used securely. New development projects must consider security<br />
requirements at an early stage.</li>
<li><strong><span style="color: #888888;">Project Leaders</span></strong> These people ensure that Security guidelines are adhered to in projects.</li>
<li><strong>Line Managers</strong> These managers ensure that their personnel are fully aware of security<br />
policies and do not provide objectives that conflict with policy. He/she enforces policy<br />
and checks actual progress.</li>
<li><strong>Users</strong> Users, or “information processors/operators,” are responsible for their actions.<br />
They are aware of company security policy, understand what the consequences of their<br />
actions are, and act accordingly. They have effective mechanisms at their disposal so that<br />
they can operate with the desired level of security. Should users receive confidential<br />
information that is not classified, they are responsible for the classifying and distribution<br />
of this information.</li>
<li><strong>Auditor</strong> The auditor is an independent person, within or outside the company, who<br />
checks the status of IT security, much in the same way as a Financial Auditor verifies the<br />
validity of accounting records. It is important that the Auditor be independent, not being<br />
involved in security administration. Often external consultants fulfill this role, since they<br />
can offer a more objective view of policies, processes, organizations, and mechanisms.</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.kreslavsky.com/2008/12/job-roles-and-responsibilities-sox-audit.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Strategies for Auditing</title>
		<link>http://www.kreslavsky.com/2008/11/strategies-for-auditing.html</link>
		<comments>http://www.kreslavsky.com/2008/11/strategies-for-auditing.html#comments</comments>
		<pubDate>Sun, 23 Nov 2008 04:52:26 +0000</pubDate>
		<dc:creator>Gil Kreslavsky</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Server 2003]]></category>
		<category><![CDATA[Server 2008]]></category>
		<category><![CDATA[Sox]]></category>
		<category><![CDATA[Active Management]]></category>
		<category><![CDATA[Attempts]]></category>
		<category><![CDATA[Auditing]]></category>
		<category><![CDATA[Bear In Mind]]></category>
		<category><![CDATA[Capability]]></category>
		<category><![CDATA[Enormous Log]]></category>
		<category><![CDATA[Failure Events]]></category>
		<category><![CDATA[Log Management]]></category>
		<category><![CDATA[Logs]]></category>
		<category><![CDATA[Managing Security]]></category>
		<category><![CDATA[Problem Users]]></category>
		<category><![CDATA[Profile Account]]></category>
		<category><![CDATA[Real Reason]]></category>
		<category><![CDATA[Scenarios]]></category>
		<category><![CDATA[Security Certification]]></category>
		<category><![CDATA[Security Log]]></category>
		<category><![CDATA[Spectrum]]></category>
		<category><![CDATA[Unauthorized Access]]></category>
		<category><![CDATA[Users Groups]]></category>
		<category><![CDATA[Worst Nightmare]]></category>

		<guid isPermaLink="false">http://www.kreslavsky.com/?p=334</guid>
		<description><![CDATA[Tweet Auditing enables you to monitor events associated with specific users, groups, and services. These events are recorded to the security log. The capability to monitor these events is not only useful for troubleshooting, but also is an important tool for monitoring and managing security. You learned how you can keep tabs on the actions of specific users or groups and monitor attempts at unauthorized access to the system or its resources. Although you could audit every event, doing so wouldn’t be practical because you’d place an undue load on the system and either end up with an enormous log file or spend all your time worrying about archiving the logs. The following sections examine some specific scenarios and how you might employ auditing. Leaving auditing off One option is to leave auditing off altogether, which is not a bad option in some situations. If you’re not concerned with security, you have no real reason to enable or perform auditing. Turning off auditing reduces system overhead and helps simplify log management; most organizations are (or should be) concerned with security at least to some degree, however, so this option is unlikely to fit your needs. Turning all auditing on At the other end of the auditing spectrum is complete auditing. If you’re very concerned about security or shooting for C2 security certification, this may be an option. Bear in mind, however, that your system is likely to generate a huge number of events requiring very active management of the security log. As an alternative to full logging, consider logging only failure events and not success events. Auditing problem users Certain users, for one reason or another, can become an administrator’s worst nightmare. In some cases, it’s through no fault of the user, but instead results from problems with the user’s profile, account, and so on. In other cases, the user can be at fault, frequently using the wrong password, incorrectly typing the account name, trying to log on during periods when they are not allowed, or even trying to access resources for which they have no permissions (or need). In these situations, you can monitor events associated with the given user. You may even need to retain the information for counseling or termination purposes. Which types of events you audit for a given user or group depends on the problem area. Audit account logon events, for example, if the user has trouble logging on or attempts to log on during unauthorized hours. Track object access to determine when a user or group is attempting to access a given resource such as a folder or file. Tailor other auditing to specific tasks and events generated by the user or group. Auditing administrators Auditing administrators is a good idea, not only to keep track of what administrators are doing, but also to detect unauthorized use of administrative privileges. Keep in mind, however, that auditing affects system performance. In particular, consider auditing account logon events, account management, policy change, and privilege use of [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.kreslavsky.com%2F2008%2F11%2Fstrategies-for-auditing.html&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://www.kreslavsky.com/2008/11/strategies-for-auditing.html"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.kreslavsky.com/2008/11/strategies-for-auditing.html"  data-text="Strategies for Auditing" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://www.kreslavsky.com/2008/11/strategies-for-auditing.html" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://www.kreslavsky.com/2008/11/strategies-for-auditing.html"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p>Auditing enables you to monitor events associated with specific users, groups, and services.<br />
These events are recorded to the security log. The capability to monitor these events is not only<br />
useful for troubleshooting, but also is an important tool for monitoring and managing security.<br />
You learned how you can keep tabs on the actions of specific users or groups and monitor<br />
attempts at unauthorized access to the system or its resources.</p>
<p>Although you could audit every event, doing so wouldn’t be practical because you’d place an<br />
undue load on the system and either end up with an enormous log file or spend all your time<br />
worrying about archiving the logs. The following sections examine some specific scenarios and<br />
how you might employ auditing.</p>
<h2>Leaving auditing off</h2>
<p>One option is to leave auditing off altogether, which is not a bad option in some situations.<br />
If you’re not concerned with security, you have no real reason to enable or perform auditing.<br />
Turning off auditing reduces system overhead and helps simplify log management; most<br />
organizations are (or should be) concerned with security at least to some degree, however, so<br />
this option is unlikely to fit your needs.</p>
<h2>Turning all auditing on</h2>
<p>At the other end of the auditing spectrum is complete auditing. If you’re very concerned about<br />
security or shooting for C2 security certification, this may be an option. Bear in mind, however,<br />
that your system is likely to generate a huge number of events requiring very active management<br />
of the security log. As an alternative to full logging, consider logging only failure events and not<br />
success events.</p>
<h2>Auditing problem users</h2>
<p>Certain users, for one reason or another, can become an administrator’s worst nightmare. In<br />
some cases, it’s through no fault of the user, but instead results from problems with the user’s<br />
profile, account, and so on. In other cases, the user can be at fault, frequently using the wrong<br />
password, incorrectly typing the account name, trying to log on during periods when they are<br />
not allowed, or even trying to access resources for which they have no permissions (or need). In<br />
these situations, you can monitor events associated with the given user. You may even need to<br />
retain the information for counseling or termination purposes.<br />
Which types of events you audit for a given user or group depends on the problem area. Audit<br />
account logon events, for example, if the user has trouble logging on or attempts to log on during<br />
unauthorized hours. Track object access to determine when a user or group is attempting to<br />
access a given resource such as a folder or file. Tailor other auditing to specific tasks and events<br />
generated by the user or group.</p>
<h2>Auditing administrators</h2>
<p>Auditing administrators is a good idea, not only to keep track of what administrators are doing,<br />
but also to detect unauthorized use of administrative privileges. Keep in mind, however, that<br />
auditing affects system performance. In particular, consider auditing account logon events,<br />
account management, policy change, and privilege use of an administrator only if you suspect<br />
an individual. Instead, control administrators by delegating through the wise use of groups and<br />
organizational units.</p>
<h2>Auditing critical files and folders</h2>
<p>One very common use for auditing is to track access to important folders and files. In addition<br />
to tracking simple access, you probably want to track when users make or attempt to make<br />
specific types of changes to the object, such as Change Permissions and Take Ownership. This<br />
helps you monitor changes to a folder or file that could affect security.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.kreslavsky.com/2008/11/strategies-for-auditing.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Recommended Active Directory Guidelines for SOX audit Part 1</title>
		<link>http://www.kreslavsky.com/2008/08/recommended-active-directory-guidelines-for-sox-audit-part-1.html</link>
		<comments>http://www.kreslavsky.com/2008/08/recommended-active-directory-guidelines-for-sox-audit-part-1.html#comments</comments>
		<pubDate>Wed, 20 Aug 2008 08:17:11 +0000</pubDate>
		<dc:creator>Gil Kreslavsky</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Sox]]></category>
		<category><![CDATA[Account Passwords]]></category>
		<category><![CDATA[Administrative Accounts]]></category>
		<category><![CDATA[Administrator Account]]></category>
		<category><![CDATA[Application Services]]></category>
		<category><![CDATA[Backup Applications]]></category>
		<category><![CDATA[Change Reminder]]></category>
		<category><![CDATA[Comprehensive Security]]></category>
		<category><![CDATA[Computer Accounts]]></category>
		<category><![CDATA[Default Domain]]></category>
		<category><![CDATA[Directory Password]]></category>
		<category><![CDATA[Domain Admin]]></category>
		<category><![CDATA[Domain Admins]]></category>
		<category><![CDATA[Domain Policy]]></category>
		<category><![CDATA[Generic Accounts]]></category>
		<category><![CDATA[Guest Accounts]]></category>
		<category><![CDATA[Maximum Password Age]]></category>
		<category><![CDATA[Security Policies]]></category>
		<category><![CDATA[Service Accounts]]></category>
		<category><![CDATA[Upper Case Letter]]></category>

		<guid isPermaLink="false">http://www.kreslavsky.com/?p=255</guid>
		<description><![CDATA[Tweet Part 1 Administrative Accounts Administrative accounts include that includes (Domain Admins, Enterprise Admins, and Administrators) Must have recognizable username for auditing purposes. Active Directory build in Administrator account must be renamed and password is known only to company IT director or other executive personal. On annual base Administrative accounts should be reviewed by IT director. Generic Accounts Generic accounts are general user accounts in active directory. And are aplyed by Default Domain Policy GPO ( See password Policy ) Service Accounts Service accounts are accounts used to run application services that requires domain credentials in order to function for example Backup applications . It is recommended that Service accounts will named by service name and their password set to &#8220;Never Expire&#8221; On annual base those Service Account passwords should be changed by IT team. Happens that service accounts are members of &#8220;Domain Admin group &#8221; And they should be approved by IT director. Every service account should have detailed description, of their purpose. Contractors It is recommended to put Contractors user and computer accounts in dedicate OU and apply more comprehensive security policies Every Contractor account should have detailed description, of their purpose (Department and Project) Guests Recommendation is to not use guest accounts at all Active Directory Password Policy for example &#8220;Password policy&#8221; is a set of password protection rules that apply to all company users Password must be at least 8 characters long Password must contain: At least 1 upper case letter At least 1 special character or digit. Example (*&#38;^%$#@?.&#124;~`,012345678+-*/) The password can&#8217;t contain part of username. Maximum password age should be 90 days. (Or less ) Password will automatically expire after 90 days since last change. Reminder is emailed to user 15, 7 and 1 day before password expiration. Minimum password age is 7 days. User cannot change password in less than 7 days after previous password change occurred. The system remembers 24 previous passwords. User may not use these passwords. User account is locked for 30 min after 5 sequential bad logon attempts. Service Accounts password are changed on yearly basis each 15/Jan notification is sent to IT group Delegation of Control Delegation of user management tasks to users with specific set of permissions. This responsibility should be assigned to a small number of Administration staff. User Opening Policy you should have policy that documents each new user User Maintenance Policy you should have policy that documents each change at user account security User Termination Policy you should have policy that documents each retired user Backup You must have Active directory backup policy]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.kreslavsky.com%2F2008%2F08%2Frecommended-active-directory-guidelines-for-sox-audit-part-1.html&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://www.kreslavsky.com/2008/08/recommended-active-directory-guidelines-for-sox-audit-part-1.html"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.kreslavsky.com/2008/08/recommended-active-directory-guidelines-for-sox-audit-part-1.html"  data-text="Recommended Active Directory Guidelines for SOX audit Part 1" data-count="horizontal">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://www.kreslavsky.com/2008/08/recommended-active-directory-guidelines-for-sox-audit-part-1.html" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://www.kreslavsky.com/2008/08/recommended-active-directory-guidelines-for-sox-audit-part-1.html"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><h1><strong>Part 1</strong></h1>
<p><strong>Administrative Accounts</strong><br />
Administrative accounts include that includes (Domain Admins, Enterprise Admins, and Administrators)<br />
Must have recognizable username for auditing purposes.<br />
Active Directory build in Administrator account must be renamed and password is known only to company IT director or other executive personal.<br />
On annual base Administrative accounts should be reviewed by IT director.</p>
<p><strong>Generic Accounts</strong><br />
Generic accounts are general user accounts in active directory.<br />
And are aplyed by Default Domain Policy GPO ( See password Policy )</p>
<p><strong>Service Accounts</strong><br />
Service accounts are accounts used to run application services that requires domain credentials in order to function for example Backup applications .<br />
It is recommended that Service accounts will named by service name and their password set to &#8220;Never Expire&#8221;<br />
On annual base those Service Account passwords should be changed by IT team.<br />
Happens that service accounts are members of &#8220;Domain Admin group &#8221; And they should be approved by IT director.<br />
Every service account should have detailed description, of their purpose.</p>
<p><strong>Contractors</strong><br />
It is recommended to put Contractors user and computer accounts in dedicate OU and apply more comprehensive security  policies<br />
Every Contractor account should have detailed description, of their purpose (Department and Project)</p>
<p><strong>Guests</strong><br />
Recommendation is to not use guest accounts at all</p>
<p><strong>Active Directory Password Policy for example </strong><br />
&#8220;Password policy&#8221; is a set of password protection rules that apply to all company users</p>
<ul>
<li>Password must be at least 8 characters long</li>
<li>Password must contain:</li>
<li>At least 1 upper case letter</li>
<li>At least 1 special character or digit. Example (*&amp;^%$#@?.|~`,012345678+-*/)</li>
<li>The password can&#8217;t contain part of username.</li>
<li>Maximum password age should be 90 days. (Or less )</li>
<li>Password will automatically expire after 90 days since last change.</li>
<li>Reminder is emailed to user 15, 7 and 1 day before password expiration.</li>
<li>Minimum password age is 7 days.</li>
<li>User cannot change password in less than 7 days after previous password change occurred.</li>
<li>The system remembers 24 previous passwords. User may not use these passwords.</li>
<li>User account is locked for 30 min after 5 sequential bad logon attempts.</li>
<li>Service Accounts password are changed on yearly basis each 15/Jan notification is sent to IT group</li>
</ul>
<p><strong>Delegation of Control</strong><br />
Delegation of user management tasks to users with specific set of permissions.<br />
This responsibility should be assigned to a small number of Administration staff.</p>
<p><strong>User Opening Policy</strong><br />
you should have policy that documents each new user</p>
<p><strong>User Maintenance Policy</strong><br />
you should have policy that documents each change at user account security</p>
<p><strong>User Termination Policy</strong><br />
you should have policy that documents each retired user</p>
<p><strong>Backup</strong><br />
You must have Active directory backup policy</p>
]]></content:encoded>
			<wfw:commentRss>http://www.kreslavsky.com/2008/08/recommended-active-directory-guidelines-for-sox-audit-part-1.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

