The first thing to audit is the security policy. If any 'holes' are found then ultimately it is the security policy that is at fault, or the security policy has not been adhered to....