Problem
Excessive auditing can degrade the performance of a system. So how much auditing is appropriate? In addition: Who should be conducting the audits, an internal entity or should it be contracted out to external auditors? Who in an organization has the ultimate say in what should or should not be audited? How do we avoid potential conflict between auditors and system developers and administrators?