{"id":15708,"date":"2019-07-04T02:30:07","date_gmt":"2019-07-04T10:30:07","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2019\/07\/04\/news-9455\/"},"modified":"2019-07-04T02:30:07","modified_gmt":"2019-07-04T10:30:07","slug":"news-9455","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2019\/07\/04\/news-9455\/","title":{"rendered":"Throwback Thursday: Spoilsport"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/article\/2019\/05\/cw_sharktank_3x2_2400x1600_01-100796357-large.3x2.jpg\"\/><\/p>\n<p><strong>Credit to Author: Sharky| Date: Thu, 04 Jul 2019 03:00:00 -0700<\/strong><\/p>\n<p>This IT security pilot fish knows something about audits \u2014 and knows what he expects of auditors.<\/p>\n<p>\u201cI have more than 15 years of audit experience in IT,\u201d fish says. \u201cI have written and implemented policy and procedure, and developed incident response plans. I spent the better part of last year making sure that the external auditors could not find any inconsistencies in our control standards.\u201d<\/p>\n<p>Then the internal audit director decides to perform an audit of fish\u2019s group \u2014 and sends a young auditor who thinks he knows everything IT.<\/p>\n<p>After three weeks of research and testing, young auditor presents his results in a meeting with his boss the audit director and fish.<\/p>\n<p>Among other findings, young auditor reports: \u201cAs a good practice, all company policies and procedures must include a disaster recovery plan &#8230;\u201d<\/p>\n<p>Fish\u2019s response: \u201cPlease indicate how a policy can contain a disaster recovery plan, and why a policy would need one.\u201d<\/p>\n<p>That momentarily slows young auditor down, but then he plows ahead with another shot: IT needs \u201ca schedule for planned reviews and updates, as well as for unscheduled changes or significant changes to the environment.\u201d<\/p>\n<p>Fish\u2019s calm response: \u201cSo your finding is that IT does not have a schedule of reviews and updates for unscheduled changes in the environment? Please tell me how we are to implement that.\u201d<\/p>\n<p>Young auditor\u2019s testy reply: \u201cIt is not internal audit\u2019s job to tell you how to correct these findings!\u201d<\/p>\n<p>\u201cThe audit director left the room red-faced and with smoke coming from the ears,\u201d reports fish.<\/p>\n<p>\u201cA battle of wits is so unfair when the opponent is unarmed.\u201d<\/p>\n<p><strong>Sharky trusts your wits.<\/strong> <em>Send me your true tales of IT life<\/em> <em>at <a href=\"mailto:sharky@computerworld.com\" rel=\"nofollow\">sharky@computerworld.com<\/a>. You can also subscribe to the <a href=\"http:\/\/www.computerworld.com\/newsletters\/signup.html\" rel=\"noopener\" target=\"_blank\">Daily Shark Newsletter<\/a> and read some great old tales in the <a href=\"https:\/\/www.computerworld.com\/search?query=+sharky&amp;s=d&amp;start=0\" rel=\"noopener\" target=\"_blank\">Sharkives<\/a>.<\/em><\/p>\n<p><a href=\"https:\/\/www.computerworld.com\/article\/3405889\/throwback-thursday-spoilsport.html#tk.rss_security\" target=\"bwo\" >http:\/\/www.computerworld.com\/category\/security\/index.rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/article\/2019\/05\/cw_sharktank_3x2_2400x1600_01-100796357-large.3x2.jpg\"\/><\/p>\n<p><strong>Credit to Author: Sharky| Date: Thu, 04 Jul 2019 03:00:00 -0700<\/strong><\/p>\n<article>\n<section class=\"page\">\n<p>This IT security pilot fish knows something about audits \u2014 and knows what he expects of auditors.<\/p>\n<p>\u201cI have more than 15 years of audit experience in IT,\u201d fish says. \u201cI have written and implemented policy and procedure, and developed incident response plans. I spent the better part of last year making sure that the external auditors could not find any inconsistencies in our control standards.\u201d<\/p>\n<p>Then the internal audit director decides to perform an audit of fish\u2019s group \u2014 and sends a young auditor who thinks he knows everything IT.<\/p>\n<p>After three weeks of research and testing, young auditor presents his results in a meeting with his boss the audit director and fish.<\/p>\n<p class=\"jumpTag\"><a href=\"\/article\/3405889\/throwback-thursday-spoilsport.html#jump\">To read this article in full, please click here<\/a><\/p>\n<\/section>\n<\/article>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[11062,10643],"tags":[714],"class_list":["post-15708","post","type-post","status-publish","format-standard","hentry","category-computerworld","category-independent","tag-security"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/15708","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=15708"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/15708\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=15708"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=15708"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=15708"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}