i Olivia Hodges / Unsplash

An IT Auditor’s Perspective on Auditing IT Security Departments and Professionals

I am being audited, what should I know before the auditors arrive? Who gets interviewed? Are there different types of audits and does this one matter? The auditors are using unfamiliar terms! Should I prepare? What are “findings” and “observations” and am I getting fired? How long do I have to correct the items?

A few thoughts: When confronted with new equipment on the network, the first answer is not “no”, but more about how can we secure it. When reviewing a new vendor access request, the conversation focuses on how our organization can control when the vendor is accessing our systems. When we send data externally, we verify it is encrypted or de-identified, and that the vendor is capable of managing the data within their systems. Deliver one strategy power point per month to communicate and align efforts. Practice incident response frequently even on low risk events to keep the process alive.

Industries covered: Financial services “Gramm-Leach-Bliley Act (GLB Act or GLBA) regulated”, healthcare “HIPAA regulated”, and food distribution (mostly unregulated for IT).

Speaker Bio

Graduate of Ferris State University with Bachelors in Computer Information Systems (CIS)

Memberships:

  • ISC2 West Michigan Chapter
  • ISACA West Michigan Chapter
  • WMCSC West Michigan Cyber Security Consortium
  • MiHCC Michigan Healthcare Cyber Security Council