    On Wed, 28 Apr 2004, Starford, Christopher D. wrote:

    > Harlan,
    > I believe many true IT Security Auditors out there would agree that your
    > wrong on this one.

    Yet, audits in the corp env's tend to focus not on IT nor security, but
    bean-counting. I've seen as HYarlan mentions that the vast majority of
    auditors have been of the finnancial category, and clueless about IT and
    it's processes and such. Now, this is not the auditors fault, but
    managments, as well as that of the partnering companies that make the
    request and hire in the wrong folks.

    Of course then there are the snack-oil IT folks, those that pentest and
    such with a point and click tool and canned report. A thourough IT sec
    audiit requires that the audirot become familiar with the org being
    audited and actually look into system configs. There are many issues in
    how systems are confuifugered that a point and launch tool are not going
    to uncover and a canned report will not mention.


