EconPapers    
Economics at your fingertips  
 

Active Directory security: Why we fail and what auditors miss

Sylvain Cortes
Additional contact information
Sylvain Cortes: Tenable, France

Cyber Security: A Peer-Reviewed Journal, 2022, vol. 6, issue 1, 41-51

Abstract: The task of a security auditor is not an easy one. Organisations depend heavily on regular audits to analyse and evaluate the risks related to their IT assets. Unfortunately, traditional auditing methods do not adequately assess the latent risks present in Active Directory (AD). This paper will help readers understand the specific challenges and pitfalls associated with auditing AD and to adapt the method to avoid a false sense of security. It concludes that it is critical to maximise auditing assignments to obtain a clear and precise view of the important remediation tasks to come.

Keywords: audit; auditor; active directory; security; ransomware; malware; lateral movement; privileges escalation; domain dominance; backdoor (search for similar items in EconPapers)
JEL-codes: M15 (search for similar items in EconPapers)
Date: 2022
References: Add references at CitEc
Citations:

Downloads: (external link)
https://hstalks.com/article/7180/download/ (application/pdf)
https://hstalks.com/article/7180/ (text/html)
Requires a paid subscription for full access.

Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.

Export reference: BibTeX RIS (EndNote, ProCite, RefMan) HTML/Text

Persistent link: https://EconPapers.repec.org/RePEc:aza:csj000:y:2022:v:6:i:1:p:41-51

Access Statistics for this article

More articles in Cyber Security: A Peer-Reviewed Journal from Henry Stewart Publications
Bibliographic data for series maintained by Henry Stewart Talks ().

 
Page updated 2025-03-19
Handle: RePEc:aza:csj000:y:2022:v:6:i:1:p:41-51