When a majority of all system processing was done on legacy systems,
information systems audit professionals recommended the protection of these
systems largely through physical security measures. By locating the data
center either on the top floor of the building or in the basement with
secured points of entry and exit, by installing a swipe card system and by
regularly reviewing its access logs, the facility and its processing were
protected from intrusions. Threats were largely internal - posed by the
disgruntled employee attempting to sabotage the last program he had worked on
prior to his departure, or by the opportunistic system operator, hoping to
pilfer a copy of a customer list to sell to a competitor.
Those were the "good ole days." Now, information systems audit professionals
wish that the problems were so simple. With the growth of the World Wide Web,
n... (more)