This is Part 2 of a document created to identify leading practices for auditing IT controls. The presentation addresses risk objectives and control points, and notes recommended parameters and minimum settings for Windows 2000 and Sun Solaris as well as several email, network and database applications.