Jump to content

Recommended Posts

Posted

I've looked at the post about ICT Internal Audit in General and can see some useful audit information but I was thinking about how to audit ourselves so we can ensure that users have the correct access rights and level of permissions for their role etc.

 

In the past I have highlighted users with rights higher than their role but the powers that be have decided that was OK. With the increased amount of Ransomware we have had in the last year I am getting rather annoyed as it is always me that has to resolve the issue. Rather than just go and run reports and then say to people you shouldn't be in the Domain Admin group. I would like to run a basic internal audit which can be used 2 fold. At the first point I would like to know we are applying the correct level of access for staff (all staff not just IT) and secondly I would like to update IT user permission to be correct for the role NOT the person. I then want to be able to hit people over the head with it when things go wrong

 

So far all I can think of is a few requirements

  • Identify IT roles (and level of access required)
  • Check group membership for IT Staff
  • Check group membership for each department and email HOD with users to check if this is correct.

 

We grant access to shared work areas & mail accounts only when we have authorisation on our ticketing system so this will log changes. However, we generally do not ever do a check to ensure the existing settings are correct meaning if something has been applied which is wrong it will stay wrong until someone notices (which would only ever be when a problem has occurred)

 

Has anyone done something like this already?

 

Disclaimer - I am just one member of the team and this is something I am thinking of doing off my own back. I will probably have the backing of my Line Manager but already know that we do things which are not considered best practice and would like to get something which we could use to highlight areas we could improve and also the risks of anything found. I'm getting a little fed up of highlighting issues that are being caused by other members of staff which cause problems for me, if after putting something in writing it is still considered OK, then I want to be able to use this as a cover my a$$ when things go wrong.

  • 2 weeks later...
Posted

Do you also have separate accounts for IT staff to perform admin functions vs their day to day accounts? If not, that's probably one worth implementing (and it's probably worth only allowing the privileged accounts to logon to servers).

 

I'd also suggest that it's worth doing a general audit of file permissions (PowerShell is probably easiest). Simple things to look for are permissions assigned to groups where there should be users or vice-versa; folders being shared with the wrong group, or things like permissions assigned to "Authenticated Users" or "Everyone" if that's not required.

 

Nested groups is also worth a look, to make sure you haven't got a group that's in a group that's in a group that's in domain admins or similar.

 

Lastly, it's worth limiting membership of the Enterprise and Schema admin groups to very few users (less than your domain admins), as they can do lots of damage (like change the rules of your AD environment.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...