Security Audit Report
The
security audit report is the security work
product that documents the results of a security audit.
The typical objectives of the security audit report are
to:
The typical benefits of the security audit report are
to:
- Ensure that each application has an appropriate approach
to security.
- Ensure that all aspects of security are addressed.
The typical contents of the security audit report are:
-
- Security Threat Analysis:
- Denial Of Service
- Fraud
- Impersonation
- Privacy Violation
- Repudiation
- Sabotage
- Theft
- Vandalism
- Virus
- Appendices:
- Major Issues
- TBDs
- Assumptions
The typical stakeholders of the security audit report
are:
The security audit report typically can be started if the
following preconditions hold:
The security audit report typically has the following
inputs:
- Work products:
- Stakeholders:
Guidelines
- The security requirements for individual applications are
documented in the associated System Requirements
Specifications.
- The security mechanisms for individual applications are
documented in the associated software architecture
documents.
Conventions
The security audit report is typically constrained by the
following conventions:
-
Content and Format Standard
-
MS Word Template
-
XML DTD
-
Inspection Checklist
-
Example Security Audit Report