Secure Coding mailing list archives

Question on ISACA


From: James.McGovern at thehartford.com (McGovern, James F. (eBusiness))
Date: Wed, 4 Nov 2009 10:38:12 -0500

John Morency of Gartner just finished giving a presentation to our IT
executives and one of the observations is that IT auditors have zero
clue as to how to audit a secure coding practice. IT audit right now is
limited to simply looking at "control" documents and viewing things
through the lens of "infrastructure". Is there something we as a
community should be doing to make auditors smarter?
************************************************************
This communication, including attachments, is for the exclusive use of addressee and may contain proprietary, 
confidential and/or privileged information.  If you are not the intended recipient, any use, copying, disclosure, 
dissemination or distribution is strictly prohibited.  If you are not the intended recipient, please notify the sender 
immediately by return e-mail, delete this communication and destroy all copies.
************************************************************
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://krvw.com/pipermail/sc-l/attachments/20091104/1b73dec6/attachment.htm>


Current thread: