﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>SQLServerCentral / SQL Server 7,2000 / Sarbanes-Oxley  / Auditor Knowledge of Database Environment / Latest Posts</title><generator>InstantForum.NET v2.9.0</generator><description>SQLServerCentral</description><link>http://www.sqlservercentral.com/Forums/</link><webMaster>notifications@sqlservercentral.com</webMaster><lastBuildDate>Thu, 23 May 2013 11:29:44 GMT</lastBuildDate><ttl>20</ttl><item><title>RE: Auditor Knowledge of Database Environment</title><link>http://www.sqlservercentral.com/Forums/Topic305599-161-1.aspx</link><description>Thanks Eric.  In the four years the thread has been open that's probably the most effort anyone has put into the answer.  It's not what I was really looking for, but at least you didn't descend into insulting the auditors.  I think they largely do a responsible job under varying levels of cooperation.My interest was in knowing whether people were experiencing something similar to what I experienced at the time.  Auditors appeared to put greater emphasis on application security, configuration and change management than they did on the database environment.  I'm also curious whether DBAs who understand the power of the environment they work in think that is appropriate.Thanks again.</description><pubDate>Tue, 14 Sep 2010 08:44:44 GMT</pubDate><dc:creator>JunkMail Victim</dc:creator></item><item><title>RE: Auditor Knowledge of Database Environment</title><link>http://www.sqlservercentral.com/Forums/Topic305599-161-1.aspx</link><description>[quote][b]JunkMail Victim (9/1/2006)[/b][hr]I've found them to concentrate on the compiled executables of the client applications, but not think much about the unencrypted business logic that resides in stored procedures and triggers inthe database environment. In our case, they seem to think of databases as only data storage, and don't consider how powerful and immediate the environment really is.[/quote]The fact that stored procedures, triggers, views and other database objects containing SQL are not encrypted (or at best weakly encrypted) is really not an issue. By default, a user account that is not a member of the DBO or sysadmin role doesn't have VIEW SCHEMA, ALTER TRACE, VIEW SERVER STATE, etc. permission unless you explicitly grant it to them, so they shouldn't be able to see the SQL. A user account for use by the application should be a member of a role that grants them only exec permission on specific stored procedures and maybe access to some tables. That's what the auditor should be looking for.</description><pubDate>Tue, 14 Sep 2010 07:46:20 GMT</pubDate><dc:creator>Eric M Russell</dc:creator></item><item><title>RE: Auditor Knowledge of Database Environment</title><link>http://www.sqlservercentral.com/Forums/Topic305599-161-1.aspx</link><description>[quote][b]Ninja's_RGR'us (9/13/2010)[/b][hr][quote][b]GilaMonster (9/13/2010)[/b][hr]Please note: 4 year old thread.[/quote]Are they any less clueless now?Not from what I've seen here.[/quote]Doubt it. That would violate the law of conservation of cluelessness.</description><pubDate>Mon, 13 Sep 2010 13:52:45 GMT</pubDate><dc:creator>GilaMonster</dc:creator></item><item><title>RE: Auditor Knowledge of Database Environment</title><link>http://www.sqlservercentral.com/Forums/Topic305599-161-1.aspx</link><description>[quote][b]GilaMonster (9/13/2010)[/b][hr]Please note: 4 year old thread.[/quote]Are they any less clueless now?Not from what I've seen here.</description><pubDate>Mon, 13 Sep 2010 13:32:32 GMT</pubDate><dc:creator>Ninja's_RGR'us</dc:creator></item><item><title>RE: Auditor Knowledge of Database Environment</title><link>http://www.sqlservercentral.com/Forums/Topic305599-161-1.aspx</link><description>Please note: 4 year old thread.</description><pubDate>Mon, 13 Sep 2010 13:27:55 GMT</pubDate><dc:creator>GilaMonster</dc:creator></item><item><title>RE: Auditor Knowledge of Database Environment</title><link>http://www.sqlservercentral.com/Forums/Topic305599-161-1.aspx</link><description>Most auditors are clueless, IMHO. Many times I think they focus on paperwork instead of actually examining the environment.</description><pubDate>Mon, 13 Sep 2010 13:13:58 GMT</pubDate><dc:creator>chrisn-585491</dc:creator></item><item><title>RE: Auditor Knowledge of Database Environment</title><link>http://www.sqlservercentral.com/Forums/Topic305599-161-1.aspx</link><description>I've experienced some auditories, and my conclusion is that in many of the cases auditors don't have a deep knowledge of whatever are they auditing and they are following a checklist.</description><pubDate>Fri, 20 Jun 2008 01:29:37 GMT</pubDate><dc:creator>Ramon Jimenez</dc:creator></item><item><title>RE: Auditor Knowledge of Database Environment</title><link>http://www.sqlservercentral.com/Forums/Topic305599-161-1.aspx</link><description>The last thing I want to do is push an auditor into doing a deeper audit, but they don't seem to understand tiered architecture.  I would agree with you that they're working with a checklist, and don't know when they should look deeper.</description><pubDate>Tue, 12 Sep 2006 10:48:00 GMT</pubDate><dc:creator>JunkMail Victim</dc:creator></item><item><title>RE: Auditor Knowledge of Database Environment</title><link>http://www.sqlservercentral.com/Forums/Topic305599-161-1.aspx</link><description>seems pretty obvious to me that the auditors we got really have no understanding of what they are asking for.  most of things they ask for or find are being read from a list of common best practices in the industry</description><pubDate>Tue, 12 Sep 2006 10:32:00 GMT</pubDate><dc:creator>Angel Garcia</dc:creator></item><item><title>Auditor Knowledge of Database Environment</title><link>http://www.sqlservercentral.com/Forums/Topic305599-161-1.aspx</link><description>No one has responded to this topic yet. Even if you don't have a complete answer, the original poster will appreciate any thoughts you have!</description><pubDate>Mon, 04 Sep 2006 08:00:00 GMT</pubDate><dc:creator>Site Owners</dc:creator></item><item><title>Auditor Knowledge of Database Environment</title><link>http://www.sqlservercentral.com/Forums/Topic305599-161-1.aspx</link><description>&lt;P&gt;Now that most companies have gone through at least one round of SOX, I'm wondering what everyone's assessment of the auditor's understanding of the database environment is.&lt;/P&gt;&lt;P&gt;I've found them to concentrate on the compiled executables of the client applications, but not think much about the unencrypted business logic that resides in stored procedures and triggers in the database environment.  In our case, they seem to think of databases as only data storage, and don't consider how powerful and immediate the environment really is.&lt;/P&gt;&lt;P&gt;There's probably a mosaic of response depending on what auditor companies have had, but I'm curious what everyone's experience has been.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description><pubDate>Fri, 01 Sep 2006 05:13:00 GMT</pubDate><dc:creator>JunkMail Victim</dc:creator></item></channel></rss>