While doing an internal audit of a manufacturing concern I found out that some of the computers used by employees of auditee organization were having chat messengers like Yahoo messenger & gtalk installed . Then I checked the information security policy & SOE [Standard operating environment] document , I couldn’t find these software present in SOE & as expected no approvals were in place to install these chat clients. So I decided to record & keep evidence for the same.
Going & checking each machine taking screenshots for these machines manually was a bit of a pain. So I decided to try Belarc advisor on one machine (computer). This software exactly gives you stock of all HW & SW available on your computer with serial & license key numbers. This report can be printed or soft copy can be kept as evidence of audit. You can also try this .
Go to http://www.belarc.com/free_download.html#tips click on download.
Install it & run in on your system. It will give you this
- ҉An html report of HW available on your system with their HW IDs / serial numbers and some other details .
- Very interesting USB Storage usage in past 30 Days, This section tells you how many storage devices were connected to this system in past 30 days.
- ҉All software installed in your system with their respective keys. &
- ҉Fow all SW installed it tells you the location where these files are stored in your computer .
- Another interesting part [ you can refer to screenshot below ] of this report is SW usage statistics . It bifurcates SW usages into following parts
- SW used within last 7 days
- Used between 90 - 7 days
- Between a year - 90 days
- And a Year ago
This gives you an idea what SW to uninstall if you are short of Hard disk storage space or want to clean up your machine to reduce boot time .
These are pretty much available in each & every report. As per FAQs posted on their website local Web page and does not send up your PC profile to a Web server or anywhere else. & Its free for personal use. . Commercial version of this Software has many more features. You can check on their website .
* SOE is a list of approved software which can be installed on every computer of that organization / department without any special approval. Software which are not part of SOE require approvals from IT security officer apart from management approval. You can find details on SOE on http://en.wikipedia.org/wiki/Standard_Operating_Environment



No comments:
Post a Comment