ARE YOU PREPARED FOR A SECURITY AUDIT? In part 1 of our series, we’ll take a look at internal audits.
By Steve Berman
T
here are three words no executive wants to hear from their IT staff: "We've been breached." Any mailing or data processing company that deals with sensitive client data likely generates reams of written security policies, because let’s face it, customers want to know that their vendors take security seriously, or they won’t continue to be customers. At some point, management has likely sat down with staff, and possibly an outside consultant, to select a security framework, such as NIST SP800-53, ISO 27001, or HITRUST CSF, and complete the long process of scoping, tailoring, and documenting company procedures. Having those policies in place is a good start, but it’s only a start. Security policies are only as good as the last time they were tested. Or to use a sports or music analogy, the proficiency of play is often determined by how recently and frequently someone has practiced. A good security posture is the result of learned and
22
MARCH-APRIL 2024 | MailingSystemsTechnology.com
practiced behaviors and processes, along with proper equipment. Determining how well policies are followed and how closely written procedures describe actual practices is called auditing. There are two kinds of audits: external and internal. External audits are performed by independent, professional auditors certified in their particular field of practice. For example, a CPA would conduct a financial audit, or a SOC 1 report on Internal Control over Financial Reporting. A cybersecurity auditor conducting a SOC 2 audit would likely have a certification such as the Information Systems Audit and Control Association (ISACA) Certified Information Systems Auditor (CISA). External audits rigorously test sets of specific controls relating to proper risk management and standards. An internal audit is conducted by the company’s own staff. The purpose of an internal audit is generally to prepare for the external audit, which costs the organization significant money. Without first conducting an internal audit, the risk of major findings during the external audit is unknown. An internal audit is therefore a mandatory step before the outside firm comes in. We will be dealing with internal audits here and external audits in the next part of this series. Who Should Conduct an Internal Audit? Internal audits are commissioned by senior company management. The audit team members should be chosen from among subject matter experts who represent a wide array of departments in the organization, and the audit leader should be familiar with the relevant cybersecurity standards and policies currently in use. Management should provide the internal audit team with a charter that lays out the mission, and the independence to complete the audit and provide truthful, unbiased results. A charter may be something like: Examine all cybersecurity policies and procedures to ensure they have been reviewed and updated per the document requirements. Test at least 40% of policies against the NIST 800-53R5 standards and controls via