Overview
As an auditor, you know how to assess whether an organization’s user access controls meet industry and regulatory standards. But over the past several years, the access control story has changed; many of the “users” logging in to mission-critical servers and applications are not users at all but other applications, systems and devices. The “passwords” these systems rely on for authentication and secure communications are SSL certificates, SSH keys or asymmetric encryption keys, and IT and InfoSec auditors must assess the efficacy of the controls surrounding these keys as rigorously as they assess other access controls.






