Home > CIO News > 10 ways to prep for auditors
CIO News:
EMAIL THIS LICENSING & REPRINTS

10 ways to prep for auditors

By Charlie Russo, News Writer
29 Jun 2005 | SearchCIO.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

If you're like plenty of CIOs, compliance requirements have impacted your entire organization -- and your auditors have made surprising requests that cost you more than you anticipated.

With one year of Sarbanes-Oxley experience under their belts, IT executives have learned valuable lesssons in preparing for audits, such as establishing comparative metrics before the auditors arrive.

One tip sheet for "increasing your audibility" is available in The Visible Ops Handbook, distributed by the Information Technology Process Institute.

To date, 17,000 copies of the $19.95 handbook have been sold, according to Kevin Behr, president and founder of the Information Technology Process Institute, a not-for-profit group focused on researching, benchmarking and developing best practices for IT executives. Here is a portion of one of its popular cheat sheets, excerpted from the handbook.

  1. Ask the auditors what they are looking for before an audit. Ask them for their audit objectives, if any pre-audit checklists.
  2. Make sure to list your perceived risks. Sort them in descending order with the highest risks at the top, along with the controls you created to mitigate them.
  3. Document your preventative controls, and have detective controls in place to show they work. Document the change management process. For each authorized change, document the configuration changes from the detective controls to show that the changes made were within the scope of the work order. File the data collected about change requests and make it readily accessible. In some organizations, all of the above information lives in a physical three-ring binder.
  4. Use Change Advisory Board meeting minutes to show that meetings are being attended and used to manage change.
  5. Keep a current and accurate asset inventory of hardware and software.
  6. Document all internal audit procedures. For example, if your policies state that firewall logs are monitored by a system with exceptions reviewed, then you must have proof of following that policy through logs of one form or another.
  7. Document all outages and unscheduled downtime in the systems along with corrective actions taken.
  8. Keep current documentation of all exceptions to policies.
  9. List any security incidents along with corrective actions taken.
  10. Be able to produce previous audit findings, analysis of the findings and progress made against findings that warranted corrective action.

"More control doesn't equal more bureaucracy equals more work," Behr said. "It turns out, those with control can do more with less and do it more quickly and with better quality."



Sound Off! -   Be the first to post a message to Sound Off!


Tags: HIPAA compliance managementInformation technology auditingCompliance strategies and best practicesSarbanes-Oxley Act (SOX) compliance managementVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2007 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts