Publication:
Automated IT Audit of Windows Server Access Control

dc.contributor.authorSutthinee Pongsrisomchaien_US
dc.contributor.authorSudsanguan Ngamsuriyarojen_US
dc.contributor.otherMahidol Universityen_US
dc.date.accessioned2020-01-27T08:36:13Z
dc.date.available2020-01-27T08:36:13Z
dc.date.issued2019-04-29en_US
dc.description.abstract© 2019 Global IT Research Institute (GIRI). To protect sensitive information of an organization, we need to have proper access controls since several data breach incidents were happened because of broken access controls. Normally, the IT auditing process would be used to identify security weaknesses and should be able to detect any potential access control violations in advance. However, most auditing processes are done manually and not performed consistently since lots of resources are required; thus, the auditing is performed for quality assurance purposes only. This paper proposes an automated process to audit the access controls on the Windows server operating system. We define the audit checklist and use the controls defined in ISO/IEC 27002:2013 as a guideline for identifying audit objectives. In addition, an automated audit tool is developed for checking security controls against defined security policies. The results of auditing are the list of automatically generated passed and failed policies. If the auditing is done consistently and automatically, the intrusion incidents could be detected earlier and essential damages could be prevented. Eventually, it would help increase the reliability of the system.en_US
dc.identifier.citationInternational Conference on Advanced Communication Technology, ICACT. Vol.2019-February, (2019), 539-544en_US
dc.identifier.doi10.23919/ICACT.2019.8701931en_US
dc.identifier.issn17389445en_US
dc.identifier.other2-s2.0-85065666524en_US
dc.identifier.urihttps://repository.li.mahidol.ac.th/handle/20.500.14594/50850
dc.rightsMahidol Universityen_US
dc.rights.holderSCOPUSen_US
dc.source.urihttps://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=85065666524&origin=inwarden_US
dc.subjectEngineeringen_US
dc.titleAutomated IT Audit of Windows Server Access Controlen_US
dc.typeConference Paperen_US
dspace.entity.typePublication
mu.datasource.scopushttps://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=85065666524&origin=inwarden_US

Files

Collections