-
Leonardo commented on the post, Discussion Question: Key Points, on the site 2014 Spring – Data Analytics for IT Auditors 10 years, 6 months ago
I guess I would have to say that the key point of the class is that data never lies, but it sometimes provides too much information to be useful. So to truly make use of data a person has to learn the tools and […]
-
Leonardo commented on the post, Discussion Question: Far Side of the Distribution, on the site 2014 Spring – Data Analytics for IT Auditors 10 years, 6 months ago
The ideas in this article can be applied to a lot of elements of security. While the article focuses on the speed of the millions of transactions being run, the idea of “shining a light” on what is past the 99th […]
-
Leonardo commented on the post, Discussion Question: Visualization, on the site 2014 Spring – Data Analytics for IT Auditors 10 years, 6 months ago
Since we talk so much about data and analysis in this class I thought this would be a good article to share with all of you. […]
-
Leonardo commented on the post, Current Affairs Topics Discussion for 14 April, on the site CYBER SECURITY: BUSINESS STRATEGY AND CYBER BATTLES 10 years, 6 months ago
http://krebsonsecurity.com/2014/04/crimeware-helps-file-fraudulent-tax-returns/
Crackers have found a way to steal information from the HR departments of companies to steal information for the sake of filing […]
-
Leonardo commented on the post, Discussion Question: Visualization, on the site 2014 Spring – Data Analytics for IT Auditors 10 years, 6 months ago
I prefer mindmaps over most types of visualization because the process of creating a mind map can also help you to see connections that you could not see before. Because the mind map deals more with concepts than […]
-
Leonardo commented on the post, Current Affairs Topics Discussion for 14 April, on the site CYBER SECURITY: BUSINESS STRATEGY AND CYBER BATTLES 10 years, 6 months ago
We have all read about the heartbleed vulnerability. The revelation that the NSA may have been aware of the […]
-
Leonardo commented on the post, Discussion Question: Goodbye Microsoft XP, on the site 2014 Spring – Data Analytics for IT Auditors 10 years, 7 months ago
Here is one of the “Hacks” that applies to ATMs. If the Hacker is going to do all this work, then they are going to be able to get around most of the defenses an OS could provide.
-
Leonardo commented on the post, Discussion Question: Goodbye Microsoft XP, on the site 2014 Spring – Data Analytics for IT Auditors 10 years, 7 months ago
I have no read any information anywhere to make me think that ATMs will be more vulnerable after Microsoft discontinues its support of XP. The hacks of ATMs that I have seen involved some sort of modification of […]
-
Leonardo commented on the post, Discussion Question: How do you detect fraud?, on the site 2014 Spring – Data Analytics for IT Auditors 10 years, 7 months ago
I agree with both of the comments above regarding unusual behavior. Although an auditor might want to keep in mind that workaholics do exist. The problem is when a person will not let go of work and moves to […]
-
Leonardo commented on the post, Discussion Question: Target Data Breach, on the site 2014 Spring – Data Analytics for IT Auditors 10 years, 7 months ago
I’m not going to discuss what went wrong with the Target case, but I think that Oyin raises a great point with her questions. Why was there such a mismanagement of the situation? We all read the things that went […]
-
Leonardo commented on the post, Discussion Question: Theme-Park Visitor Tracking, on the site 2014 Spring – Data Analytics for IT Auditors 10 years, 7 months ago
If I were a consultant at Disney I would worry about data leaks, and people stealing the information of other guests or using the accounts of other guests to make purchases. It has been documented that RFID […]
-
Leonardo commented on the post, Discussion Question: ERD and primary keys, on the site 2014 Spring – Data Analytics for IT Auditors 10 years, 7 months ago
What advice would you give to make sure an ERD accurately represents the business event it is supposed to capture?
I would have the databases end users involved in the design of the ERD. Although a database […]
-
Leonardo commented on the post, Data Theft: This Time It's Personal, on the site 2014 Spring – Data Analytics for IT Auditors 10 years, 8 months ago
1.As many people have mentioned this information is sufficient for a person to commit credit card fraud or to find out more about you. Once you have a person’s name, social, and date of birth its not difficult to […]
-
Leonardo commented on the post, Recruiting Fraud, on the site 2014 Spring – Data Analytics for IT Auditors 10 years, 8 months ago
I found this article about the bell curve to be pretty interesting.
-
Leonardo commented on the post, Recruiting Fraud, on the site 2014 Spring – Data Analytics for IT Auditors 10 years, 8 months ago
I agree with Oyin, in that the incentives were focused on the wrong people and gaming the system was entirely too easy.
While active recruiting is always difficult this system is entirely too easy to abuse […]
-
Leonardo commented on the post, Loss Prevention Metrics, on the site 2014 Spring – Data Analytics for IT Auditors 10 years, 8 months ago
I would focus on perimeter security and network security.
on a daily basis I would monitor intrusions, depth of penetration, and network traffic and outgoing traffic.
on a weekly basis I would monitor […] -
Leonardo commented on the post, Happy Birthday SNL // the typists from the Carol Burnett show, on the site 2014 Spring – Data Analytics for IT Auditors 10 years, 9 months ago
What’s an example of knowledge you possess–something you know?
What is the line between knowledge and skills that have been acquired? I agree with Oyin, in the article by Mr. Weinberger is that he seems to be […]
-
Leonardo commented on the post, Why would you perform a continuous audit?, on the site 2014 Spring – Data Analytics for IT Auditors 10 years, 9 months ago
Continuous Audit is a useful technique for various reasons:
-it increases control effectiveness
-it enables quick response
-it sets the right tone if supported by management
-It can help create benchmarks […] -
Leonardo commented on the post, ICE 5.1 Telling a Story through Visualization, on the site 2014 Spring – Data Analytics for IT Auditors 10 years, 9 months ago
Just got your email. Looking forward to class next week.
-
Leonardo changed their profile picture 11 years, 1 month ago