Do you audit users with Sudo access and a log of sudo activity or just users with access to sudo?

like
Posting as :
works at
You are currently posting as works at

Just an A1 here, but I’ve seen us test users with sudo access for appropriateness and/or implement a control that requires users to obtain approval to the use the root account, and then a ticket gets automatically created with the log of the actions the user performed which gets reviewed and approved.

like

If you find yourself needing to go down the route of auditing user activity who have sudo access, then what you're really looking at is a finer SOD issue. In this case, I would not really do an exhaustive user activity test as long as I can obtain evidence of two or three instances of sudo user activity that does not align with the R&R

I would say a point in time test of users is pretty weak (but not unheard of if there arent many users or if the company is small). Typically id like to see a UAR unless inappropriate sudo access has been identified as a problem in the past in which case an activity review may be appropriate. At the end of the day tho - you're testing the client's controls and whatever they have in place is what you test. You can identify a control gap if you feel their control is inadequate to address the risk but you can't test what they're not doing 🤷‍♂️

You define what privileges you’re looking for first and then use the sudoers file to figure out who can access those privileges. If you’re ever needing to track OS activity you’re already pretty fucked unless the client has some sort of monitoring programs in place.

Related Posts

where can i find free resume template , I have checked the outlook template but those are not impressive..any website, please advise ?

like

Where can i buy preowned LV or chanel bags? Any recommendation on genuine online retailers/stores y’all used?

Any referrals of banking domain? I have experience for almost 6 years in TCS.

like

First time home buyers in the GTA: where are we moving to? I'm considering a 1500 sq ft igloo in Nunavut at this point.

funnylike
like

Hi All!
Anyone from the insurance industry based in Jakarta, Indonesia? Would be happy to connect/network over coffee

like

Anyone know when promotions are happening? 👀

likefunny

What are ways to get more vacation time?

I’m feeling a little suffocated with the standard two weeks with all my family events this year.

Yet another town hall where all we hear about is hiring more senior leaders vs promoting talent from within (especially women of color)…

like

please help me get to 11 likes to unlock the messaging features. Thanks a ton in advance 😊

like

Any regular processing selections out there?

Hey! I’m planning to take an Orff Level 1 course this summer. Any tips, tricks, or advice as I prepare? Also, what other trainings would you recommend for elementary general music teachers? Thanks in advance!

like

Texas drivers…honest question. Why, why in tf do people just camp in the left lane? I’m talking doing maybe 5 mph over the limit in the left lane when people want to go faster and they can get over?? I can’t always see around and sometimes on hills I can see that one jackass is holding up a line of cars. What gives???

like

Any M 40+ in Nairobi? The apps here are not it!

like

Hello guys! This group is for Datascientists who are currently working or want to work in Accenture as DataScientists.

like

I have 1 yrs 8 months of experience. And Infosys wants two years of experience. Will my offer Lett be rejected. Infosys

like

Best pizza delivery in Boston? I really like Picco. Upper Crust is trash. Regina is decent.

like

Whoever said mixing scotch with anything is wrong - think again!

Post Photo
like

Any other RD applicants to CBS still waiting on an interview decision?

Hi all,

Joined back TCS after Sabbatical leave (higher education).

Current designation is System Engineer and role tagged on Ultimatix is Developer.

Assigned to a project as BA (orally, on paper it's just Team Member). Raised a re-fitment request to HR.

Please throw some light on the re-fitment process and what I can expect depending on my qualification.

Qualification:
> TCS : QA/Jr.BA (3yrs)
> M.Sc : CS (University of Alberta, Canada)

Thanks

like

Additional Posts in Risk Assurance

Does anyone have any good resources for auditing ESG?

What’s a good out from RA? Thinking about moving away from audit/accounting

like

When is busy season over for the SOX side of stuff? Please tell it doesn’t go past 12/31.

funny

Be honest, do you see yourself staying in the game to make partner?

likehelpful

What’s your worst experience with a senior? (As an associate)

How do you apply design factors to IT Audits. Just overheard someone explain 'level of aggregation' for IT Security policies by describing how many people have access to it. Why is this a thing???

like

I currently work in a Chief Internal Auditor role. I want to get a certification focused on IT audit both for knowledge, gaining credibility with my stakeholders in the IT audit space, and for when I look for a new role. I don’t have / won’t be able to get sufficient IT audit experience for the CISA designation at this stage. What designations, courses, or other options would you suggest?

like

How do you explain SOX/SOC compliance to your friends or family? When I try to explain that I don’t do Tax or Audit they’re so confused.

like

How do we shift to investment banking/wealth management and is it worth it?

like

So I was offered a role in Strategy Consulting in after 2 years in Risk Consulting however, after 2 years I’ve only worked on Internal audit engagements few ad hocs such as updating risk register and the delegation of authority matrix.

Honestly speaking I am doing good and I am up for promotion in October however I am not fully enjoying my time but I fear that the move would not be a good and I can’t hit the ground running which scares me.

Any advice and past experiences in such career shit?

like

Has an tested roles for SAP through productive test simulation within production? Is there any risk doing this as the test is in production?

like

Anyone can give insight in B4 Risk in Houston/Dallas market?

like

Anyone hiring for entry level risk compliance roles?

like

Hi! I used to work at PwC and currently work at Friedman. I’ve been at Friedman for about a year and a half and I love it! We are hiring at an experienced associate and senior associate level! Cont..

like

PWC recruiter contacted me for a SA role in their Process Assurance practice in Austin. How much does it pay? And how is the work compared to external Audit?

like

Mid year promotions, I found out you need to make your own case for it rather than the firm coming to you. If you think you’re ready make sure you speak up!

For all you in IT audit what has your salary progression been YOY?

like

Any idea on what I industry senior risk analysts are making?

like

Looking for advice. I have a few offers in negotiations for Senior IT audit role. My main motive is to get out of toxic work culture in B4 consulting and public accounting. Looking for better wlb, better work culture and decent compensation to make good living. Currently in TX making around 110K TC.

1. Children’s Place: Base-110K . Probable bonus of 3-5%. No relocation assistance or sign on bonus. Based in NJ. Location is closer to all my friends and family
(Continued)

like

New to Fishbowl?

Download the Fishbowl app to
unlock all discussions on Fishbowl.
That was just a preview…
Sign Up to see all discussions
  • Discover what it’s like to work at companies from real professionals
  • Get candid advice from people in your field in a safe space
  • Chat and network with other professionals in your field
Sign up in seconds to unlock all discussions on Fishbowl.

Already a user?
Login here

Share

Embed this post

Copy and paste embed code on your site

Preview

Download the
Fishbowl app

See what’s happening in your industry
from the palm of your hand.

A phone with Fishbowl app

Scan your QR code to download
Fishbowl app on your mobile

Download app

Sign up for free to view this conversation on Fishbowl

By continuing you agree to Terms of Use and Privacy Policy

Already have an account? Log in

Sign up for free to continue using Fishbowl

By continuing you agree to Terms of Use(New) and Privacy Policy(New)
Messaging rates may apply

Already have an account? Log in

For account settings, visit Fishbowl on Desktop Browser or

General

Legal