Chapter 5

Information Security Standards and Audits

Anecdote

I don’t dislike auditors, but as a profession it does seem to attract herds of the wrong kind of people—all cufflinks and unsupported arrogance. I should know; I worked with them for long enough.

At the time I was well on the way to becoming a partner in one of these audit firms, mainly because I kept being engaged in very large security assignments. In Hong Kong, I was doing a job for a world-class bank. Everything was decidedly “barely adequate” in terms of firewalls, but I had yet to look at the routers and switches. In fact, the ...

Get How to Cheat at Managing Information Security now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.