An outside vulnerability assessment reveals that users have been routinely accessing Gmail from work for over a year, a clear violation of this organization's security policy. The users report ''it just started working one day''. Later, a network administrator admits he meant to unblock Gmail for just his own IP address, but he made a mistake in the firewall rule.
Which security control failed?
Audits are used to identify irregular activity in logged (after-the-fact) records. If this activity went unnoticed or uncorrected for over a year, the internal audits failed because they were either incomplete or inaccurate.
Authentication, access control and managing user rights would not apply as a network admin could be expected to have the ability to configure firewall rules.
Carisa
7 months agoTyra
7 months agoBette
7 months agoJanet
8 months agoAshleigh
8 months agoMarti
8 months agoBrice
8 months agoEdna
8 months agoMisty
8 months agoShonda
8 months agoSamuel
8 months agoMalcom
8 months ago