18.12.2012 Views

Proceedings

Proceedings

Proceedings

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

These four domains are interrelated; while “Plan and Organise” provides direction to<br />

solution delivery and service delivery, “Acquire and Implement” provides the<br />

solutions and passes them to be transformed into services, “Deliver and support”<br />

receives the solutions and makes them usable for the end users and “Monitor and<br />

Evaluate” monitors all processes to ensure that the direction provided is followed.<br />

Across the four domains, 34 processes are identified, each one having a number of<br />

control objectives.<br />

The principle that COBIT framework relies on, depicted in Figure 3, is that IT<br />

resources are managed by IT processes in order to achieve IT goals that respond to the<br />

business requirements.<br />

Figure 3: The COBIT Cube<br />

(Source: COBIT 4.1 Excerpt, IT Governance Institute, 2007: 25)<br />

It is worth mentioning that the level of security and controls implemented for the<br />

information systems should be correlated with the risk the respective system poses to<br />

the overall organization, therefore controls may vary depending on the level of risk<br />

identified for that particular system.<br />

3. RESEARCH APPROACH AND METHODOLOGY FOR THE ORACLE<br />

DATABASE AUDIT<br />

In the following pages we tried to propose an audit plan that best covers the databases<br />

vulnerabilities and hardening issues. The audit plan is based on literature review,<br />

COBIT framework and on our own practical experiences with databases. We analyzed<br />

the COBIT framework and we selected the processes and the relevant control<br />

objectives that are critical for the database control and we translated them into audit<br />

steps.<br />

~ 293 ~

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!