SlideShare une entreprise Scribd logo
1  sur  7
Télécharger pour lire hors ligne
AUDITORÍA DE INTRUSIÓN
  Los Tenemos Dentro



 D. Roberto Soriano Doménech
         Auditor Senior
¿Cuál es el objetivo?
            Juicios                                        Álbumes
                                   Cartas
Bancos                                                   Fotográficos

                     Proyectos

Contratos Clientes                                 Históricos
                             Datos de
                              Acceso
                     I+D+I



  Expedientes          Contratos
    Médicos                                            Experiencia
                                       Tarjetas
                                      De Crédito
¿Como?
•   Físicamente
                                                Origen de los Riesgos en SI
•   Ingeniería Social
                                                                         Errores
•   Lógica                               50
                                                                         Fraudes
     – Por desconocimiento de            40                              Sabotaje
       empleados
                                                                         Intrusos
                                         30
     – Empleados descontentos                                            Fraudes
                                         20
     – Ex empleados                                                      Fuego
                                         10
     – Expertos                                                          Inundacion
                                         0
     – Aplicaciones de coste bajo o 0.                                   Naturales
                                              Interno Externos Fisicos
     – Tutoriales
• Vulnerabilidades                        • Impacto
  – Software defectuoso.                    –   Pérdida directa de dinero.
  – Equipo configurado de forma             –   Reducción de las acciones.
    inapropiada.                            –   Pérdida de imagen.
  – Diseño deficiente de redes.             –   Pérdida de mercado.
  – Personal insuficiente.                  –   Pérdida de oportunidades.
  – Elección deficiente de contraseñas.     –   Reducción en el desempeño.
  – Tecnología no probada.                  –   Interrupción del negocio.
  – Transmisión de comunicaciones no        –   Sanciones.
    protegidas.                             –   Responsabilidad penal o civil.
  – Falta de redundancia.                   –   Conflicto de intereses.
                                            –   Violaciones a la privacidad.
¿Que Hacemos Nosotros?
• Contrato
   – Ips a probar, restricciones, técnicas aceptables, aprobación de la
     metodología, horario del ataque, IPS origen de ataque, datos de
     contacto, uso de información recogida, aviso antes del inicio.
• Evaluar todas las vulnerabilidades
                                                            NIVEL DE RIESGO
• Riesgo de las Pruebas
                                                     Bajo       Medio   Alto   Impacto
• Informe Ejecutivo.
                                         Bajo




                                         Medio




                                          Alto




                                      Probabilidad
Gracias


  Roberto Soriano, CISA

Auditor Senior de AUDITAIS

   rsoriano@auditais.es

Contenu connexe

En vedette

2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by Hubspot2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by HubspotMarius Sescu
 
Everything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTEverything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTExpeed Software
 
Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsPixeldarts
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthThinkNow
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfmarketingartwork
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024Neil Kimberley
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)contently
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024Albert Qian
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsKurio // The Social Media Age(ncy)
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Search Engine Journal
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summarySpeakerHub
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next Tessa Mero
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentLily Ray
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best PracticesVit Horky
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project managementMindGenius
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...RachelPearson36
 

En vedette (20)

2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by Hubspot2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by Hubspot
 
Everything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTEverything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPT
 
Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage Engineerings
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
 
Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 

Auditoriade Intrusion Rsd Ccrb2007

  • 1.
  • 2. AUDITORÍA DE INTRUSIÓN Los Tenemos Dentro D. Roberto Soriano Doménech Auditor Senior
  • 3. ¿Cuál es el objetivo? Juicios Álbumes Cartas Bancos Fotográficos Proyectos Contratos Clientes Históricos Datos de Acceso I+D+I Expedientes Contratos Médicos Experiencia Tarjetas De Crédito
  • 4. ¿Como? • Físicamente Origen de los Riesgos en SI • Ingeniería Social Errores • Lógica 50 Fraudes – Por desconocimiento de 40 Sabotaje empleados Intrusos 30 – Empleados descontentos Fraudes 20 – Ex empleados Fuego 10 – Expertos Inundacion 0 – Aplicaciones de coste bajo o 0. Naturales Interno Externos Fisicos – Tutoriales
  • 5. • Vulnerabilidades • Impacto – Software defectuoso. – Pérdida directa de dinero. – Equipo configurado de forma – Reducción de las acciones. inapropiada. – Pérdida de imagen. – Diseño deficiente de redes. – Pérdida de mercado. – Personal insuficiente. – Pérdida de oportunidades. – Elección deficiente de contraseñas. – Reducción en el desempeño. – Tecnología no probada. – Interrupción del negocio. – Transmisión de comunicaciones no – Sanciones. protegidas. – Responsabilidad penal o civil. – Falta de redundancia. – Conflicto de intereses. – Violaciones a la privacidad.
  • 6. ¿Que Hacemos Nosotros? • Contrato – Ips a probar, restricciones, técnicas aceptables, aprobación de la metodología, horario del ataque, IPS origen de ataque, datos de contacto, uso de información recogida, aviso antes del inicio. • Evaluar todas las vulnerabilidades NIVEL DE RIESGO • Riesgo de las Pruebas Bajo Medio Alto Impacto • Informe Ejecutivo. Bajo Medio Alto Probabilidad
  • 7. Gracias Roberto Soriano, CISA Auditor Senior de AUDITAIS rsoriano@auditais.es