Auditing Network Security
The auditor needs to obtain certain information and
understanding of the network that is under review to proceed
with the audit of network security. This information gathering
can be done in the following steps and sequence:
1. What is the network?—The first step is determining the
extent of the network. This is generally done by examining
the network diagram. The network diagram is basically a
map that shows all the routes available on the network. The
key factor that the auditor has to worry about in the diagram
is its accuracy. Large networks evolve and change constantly