Posts

Featured Post

How to Test an Information Security Control: Control → Evidence → Test → Conclusion

 A Practical Auditor’s Approach to Determining Whether a Control Really Works "A control should not be considered effective simply because evidence exists. The real test is whether the evidence demonstrates that the control operated as intended and addressed the relevant risk." An information security control can look perfectly acceptable on paper. There may be a policy. There may be a procedure. There may be screenshots. There may be reports. There may even be management approval. But when an auditor asks a more fundamental question— “How did you determine that this control actually worked?” —the assessment becomes much more interesting. Testing a control is not simply about collecting evidence and checking whether a document exists. A meaningful control test should establish a logical connection between: Risk → Control → Objective → Evidence → Test → Result → Conclusion This article presents a practical approach that auditors, GRC professionals and control ow...

When Evidence Exists but the Security Control Is Still Ineffective

 A Practical Auditor’s Guide to Moving Beyond the Checkbox "Evidence proves that something exists or occurred. Effective controls demonstrate that the intended risk is being addressed consistently." In information security audits, one of the most common mistakes is to equate the existence of evidence with the effectiveness of a control. An organization may provide a policy, system screenshot, log extract, report, approval record, or compliance certificate. At first glance, the evidence may appear sufficient. But an important audit question remains: Does the evidence actually demonstrate that the control is appropriately designed, implemented, operating consistently, and achieving its intended security objective? This distinction is particularly important in BFSI, critical applications, regulated environments, ISO/IEC 27001 implementations, and formal Information Security Management Systems (ISMS). A control can have documentation and supporting evidence and still fail t...

OWASP Top 10

Image
OWASP Top 10 is an awareness document mentioning top 10 most critical risks in web application security which is regularly updated by an international non-profit organization called Open Web Application Security Project, dedicated to web application security. 1. Broken Access Control Broken access control vulnerability allows attackers to read / view sensitive data and carry out actions that they are not authorized to carry out. As an illustration, consider a website allows only admin users to view its admin pages and protected from regular users. If access control is compromised, an unauthorized user can read private data belonging to other users, gain access to admin and carry out actions that they are not intended to. Example of such type of vulnerability is Insecure Direct Object References (IDOR). Consider a user on a website uses following URL to access his / her account: https://xyz.com/user_acct?user_num=123 Using the URL, user retrieving his information from the database in th...

TCP/IP Model

Image
TCP/IP stands for Transmission Control Protocol/Internet Protocol and is a standard protocol suite used to facilitate communication between network devices over the internet which consists of two components TCP and IP. TCP/IP is a compact form of OSI model. Unlike the OSI model, which has seven layers, it has four layers. The data is divided into packets by the TCP/IP Model at the sender's end, and in order to preserve data correctness, the same packets must be reassembled at the recipient's end. The data is divided into four layers by the TCP/IP paradigm, which arranges the data in a sequential fashion at the sender's end and reorders it at the recipient's end. TCP/IP Model- 4 Layers Network Access Layer: A combination of Physical layer & Data Link layer defined in OSI model, responsible for the transmission of the data between two devices over network. Ethernet protocol is used by this layer. Network Layer / Internet Layer: It is responsible to send the packets fr...