And Now For Something Completely Different

There was no post last Thursday as I was traveling by rail from the east coast to Colorado, where I’m spending this week. I’ll also be traveling next Thursday on the return trip back east, so there will be no post next week. With that said, I’m going to post this months And Now For Something Completely Different a week early.

I’ll also note, I like writing these posts more than the internal controls posts, so might try to find a way to post them more often, maybe one at a time, also making the posts quicker reads.


WordPress

WordPress implemented a new automated security review prior to the release of plugins. The review will assess plugins to determine their potential security risk and any that are assessed a high security risk will be blocked. This automated security review also applies to themes. It should be noted the automated review only applies to plugins and themes made available to WordPress.org self-hosted sites. I didn’t look into this, but I would assume a similar tool already existed for sites hosted on WordPress.com.


IDScan Breach

Brian Krebs once spoke at an ISACA conference I attended. Pretty sure it was in Las Vegas and he might have been the keynote speaker, but could be wrong. It was at least 10 years ago. Either way, I found his story interesting and have followed his writing since, which he does at krebsonsecurity.com. A few weeks ago he posted an article about an IDScan branch that was initial brought to his attention and later picked up by the FBI.

The article brings up some interesting thoughts regarding the dangers of requiring drivers licenses to verify identification prior to accessing services provided by social media sites in order to protect kids. These requirements are mostly being pushed by governments. However, there are some social media sites, take Gander for example, that are doing this on their own accord. I do think we need to separate the sites doing this on their own from those being forced to by governments, whereas one is a choice and the other is a requirement.

https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/


AI

The AI industry was thrown for a little loop last week when leaders in the AI industry called to slow things down. The concept is something I’m in favor of, but for different reasons.

AI is outpacing governance, which is creating unknown control risks.

I find it interesting that the request is coming from the big AI companies that are spending money hand over fist without the income to offset expenses, going into massive debt. The request isn’t coming from companies like Apple, Google, Meta, and Amazon. These are income generating companies that are mostly able to offset the expenses. Just something to keep an eye on.

https://www.theverge.com/ai-artificial-intelligence/995186/is-big-techs-ai-slowdown-a-safety-pact-or-a-cartel


That’s it for this month.

Manual vs Automated Controls

Overview

The difference between manual and automated controls completed by the service organization is pretty self-explanatory. Manual controls rely on a human action (e.g., review, signature), while automated controls are system-driven (e.g., configurations, rules), with a human only getting involved if/when there’s an error notification.

Using control 1.02 as an example, a manual control would be the hiring manager and application/data owner approval signature. Evidence of approval can be stored in a system (e.g., electronic signature in a service desk ticket), but it still requires a person to perform the action of approving access.

A simple to understand automated control would be user password settings. The settings are configured at the network or application level and apply to all users. Using control 1.03 as a more complicated example, an automated control would be disabling employee access on their last day of employment through integrations built into the Human Resources Information System (HRIS) and relevant applications/systems.

It’s also possible for a control to be both automated and manual if there are multiple aspects to the control. Continuing with control 1.03, additional steps might be needed to disable access for systems not integrated with the HRIS (e.g., facility access system).

Aside: I try to use separation instead of termination nowadays, but they are interchangeable.


Example SOC 1 control matrices for an access control objective. This is not a fully fleshed out objective and is just being used for illustrative purposes.

Testing

The type and extent of testing performed can be drastically different depending on if the control is automated or manual. Prior to testing, the service auditor will inquire with the control owner(s) to obtain an overview of the control, determine how the control is performed, and ascertain what evidence is available for inspection.

Continuing with control 1.02 as a manual control example, the service auditor will request a population of personnel hired during the period and select a sample from the population for testing. The larger the population, the larger the sample size selected for testing. There are upper limits to samples sizes, but that’s a topic for another day. The service auditor will rely on spreadsheets, exports from the ticketing system, and/or screenshots as evidence for testing to ensure approvals were obtained prior to granting system access.

Continuing with control 1.03 as an automated control example, the service auditor will still request a population of personnel separated during the period. However, since the control is automated, the service auditor will inspect automation criteria (system configuration, rules) and system logs/records for a sample of 1-2 transactions during the period. A full sample from the population based on sample selection guidelines isn’t generally required.


AI

It’s important to keep in mind when implementing AI into the internal control environment, the system should still log how and/or why decisions were made. From an internal controls and audit perspective, there needs to be evidence available to prove a control was working as expected and was effective. If there’s no proof, then it didn’t happen.

And Now For Something Completely Different

It’s the last Thursday of the month, which means it’s the day I post something completely different. Included below are a few topics and articles that I found interesting this month.

DEF CON

This story from a Delta flight from Las Vegas to Atlanta following DEF CON doesn’t necessarily bring up a new concept in hacking, though the timing definitely leaves a lot to be desired. It would seem doing something illegal while on a plane with no exit strategy isn’t the smartest idea, unless their name is DB Cooper.

Still, the story allowed me to reminisce about attending DEF CON in 2017 with some coworkers, which was an experience both during and after-hours. Most of the conference was over my head, but I did learn how to pick locks and still have a lock picking set stored somewhere.

https://arstechnica.com/information-technology/2026/08/def-con-crowd-suspected-in-fake-hotspot-attack-on-delta-flight/


Apple

Apple will send a push notification to your phone if it detects “mercenary spyware attacks” based on who you are or what you do. This is a feature Apple has had in place since 2001, but popped into the mainstream once again this past month.

Security awareness training (including phishing, vishing, and smishing) usually recommend being cautious when an email, text, or phone call comes with a sense of urgency or pressure, so this would require some thought before taking next steps if it popped on my screen.

https://techcrunch.com/2026/08/13/if-apple-sends-you-a-push-notification-alerting-you-to-a-spyware-attack-take-it-seriously/


Infrastructure

Bear with me as I go in a little circle here regarding the cyber attacks on water infrastructure in various states.

Chesterton’s Fence is “the principle that you should not remove or change a rule, system, or object until you understand why it was put there in the first place”. I learned about this principle recently, mostly because it applies to so many things happening around us.

With my prior employer, an aspect of my job responsibilities was to complete IT risk and general controls assessments for local (small) municipal and public sector entities. Something I always had to keep in mind while performing these assessment was their resource limitations, which directly affected what types of recommendations could be made.

The Cybersecurity and Infrastructure Security Agency (CISA) is a federal agency under the Department of Homeland Security (DHS) responsible for protecting the nation’s critical infrastructure and cyber defenses. CISA provides additional support for local entities, including infrastructure, that don’t have the resources to do everything on their own.

CISA’s staff dropped from roughly 3,300 to about 2,389 employees last year (2025), which is a loss of about a third of the agency. Proposed budget plans for 2027 target the elimination of ~900 additional positions.

Job cuts at CISA, limited resources at the local level, and constantly increasing cyber threats is a recipe for disaster and could make cyberattacks on our infrastructure more common and potentially successful.

This is a long winded way of noting the job cuts at CISA are not a good idea.

https://www.securityweek.com/us-water-cyberattacks-extend-beyond-minnesota-to-at-least-6-other-states/