What are the critical information assets in the network?—The
fundamental principle of information security and audit is that
protection is related to the risks associated with the assets as
determined by a systematic risk assessment. The auditor needs
to have a good idea of the critical assets, systems and services
that need to be secured. Typically, one would want to protect
enterprise systems including ERPs, mail servers and other
internal applications, web servers that host applications that
are accessed by customers and vendors, and the network and
its components. In this context, the security and access
mechanisms surrounding the applications and the servers (the
OS and database) also need to be robust