top of page
  • Facebook
  • Twitter
  • Linkedin

Understanding the CrowdStrike Software Malfunction: A Breakdown of Causes

Writer's picture: John C. Blackshire, Jr.John C. Blackshire, Jr.




The recent CrowdStrike software malfunction that led to global IT outages can be divided into proximate, intermediate, and root causes:


Proximate Causes

  • Ineffective Software Testing by the Vendor: CrowdStrike did not have robust IT General Controls in place for the development, testing, and distribution of the software release.

  • Ineffective Software Release Testing by Customers: CrowdStrike’s customers also lacked effective IT General Controls for testing the software before adoption.

  • Software Vendor Trust: A faulty update to the CrowdStrike Falcon Sensor software was trusted and implemented by customers without rigorous independent testing.

  • Software Update Error: This faulty update caused a logic error that led to system crashes and blue screens of death (BSOD) on affected Windows systems.


Intermediate Cause

  • Content Update Defect: The defect was identified in a specific content update for Windows hosts. This update introduced a malfunction in the kernel driver, which is critical for the operating system's interaction with hardware components.


Root Cause

  • Poor Update Management and Monitoring: The overarching issue lies in inadequate processes for managing and monitoring software updates. This oversight allowed a defective update to be deployed globally without sufficient testing or safeguards to prevent widespread disruption.


Summary


CrowdStrike's recent IT outage highlights the essential need for stringent update management and comprehensive testing protocols to avoid such failures in the future. Addressing these key issues is vital for maintaining trust and reliability in software deployments.

 
 
 

Comentarios


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

At CCS, we are deeply dedicated to delivering NASBA-sponsored Continuing Professional Education (CPE) training events focusing on vital subjects such as risk management, audit & assurance, internal controls, internal audit, cybersecurity, and compliance. Our educational content is meticulously crafted to be accessible through live webinars and in-person CPE events, custom-tailored to meet the CPE requirements of certifications including CIA, CPA, CISA, CFE, and other professional certifications.

We take immense pride in our pivotal role over the past twenty years of empowering participants to expand their audit expertise and develop a deep understanding of best-practice frameworks and standards established by eminent organizations such as IIA, AICPA, COSO Framework, PCAOB Auditing Standards, NAIC Model Laws, GAO Green Book, GAO Yellow Book, NIST, ISO, CMMC, ACFE, SEC, and IAASB.

Our comprehensive CPE training events provide invaluable insights across a diverse spectrum of topics, encompassing internal auditing, external audits, planning and execution of audits using the PCAOB Auditing Standards, formulation and implementation of effective internal audits, risk identification and evaluation, adherence to accounting and auditing standards, proficient management of business endeavors and projects, ITGCs and application controls, vigilant oversight of vendor and third-party risks, robust cybersecurity initiatives, and the reporting of audit, risk management, and internal control training courses.

Furthermore, we offer our professional attendees the opportunity to engage with our webinar CPE events virtually, featuring live instructors, or to participate in-person at select cities or a location of their choice.

We consider our target audience to include chief audit executives, audit partners in CPA firms, chief compliance officers, audit managers, audit supervisors, external auditors, internal auditors, internal control professionals, quality control professionals, compliance professionals, board members, and other professionals who prioritize continuous improvement and organizational sustainability.

Our CPE events are all based on the professional standards provided by the IIA, AICPA, PCAOB Auditing Standards, SEC, ISACA, ACFE, NAIC regulations, NIST, ISO, CMMC, COSO Framework, GAO Yellow Book, GAO Green Book, U.S. GAAP, IFRS, and IAASB.

The CCS training staff has a broad range of experience in internal auditing, Big 4 auditing, software development and implementation, Big 4 consulting, governmental accounting and auditing, regulatory compliance and professional training.

Our flexibility in delivering content allows us to cater to the diverse needs of our professional audit function, internal control professional and information technology participants, ensuring a truly enriching learning experience for all.

Explore our CPE event offerings and sign up for your first CPE training event today!

bottom of page