Trust is Not Really a Control, Neither is Luck

August 9, 2009 by ADMIN · Leave a Comment

By Gene Kim, CTO of Tripwire and co-founder of the IT Process Institute

This risk is often hidden in plain sight, poses a genuine clear and present danger to the business and information security objectives, and one that is often overlooked. This issue is change control.

Audits and the Change Management Process

June 29, 2009 by ADMIN · Leave a Comment

By Gene Kim, CTO of Tripwire and co-founder of the IT Process Institute

If the auditor observes that no one is showing up to the change management meetings, authorizations are rubber stamped without any real evaluation, unauthorized changes and unplanned outages are occurring regularly, then she will likely flag this as a potential high risk area.