
Again, it's time for one of the systems that our team managed to be subjected to an external audit, this is done once per three years. Unlucky me, I have been chosen to front this audit exercise.
Althought, I have had experiences dealing with auditors, but I do still get scared sometimes, not because they are intimidating, but rather, what kind of information they will try to probe. They are smart people. On our part, each question should only respond with a simple answer, no more than that. To them, people are the weakest link, so they will always focus on people questions.
Read this: "There are those who will say that network security is an oxymoron - that if you put a computer on a network, it is no longer secure. To some degree, this is true. There is no such thing as a perfectly secure network." - Randal K. Michael's AIX 5L Administration book.