Surviving a third party onsite audit

| No Comments

How serious are you about your company's information security?  You will get very serious quickly when your company is audited by a third party.  These aren't third party vendors either, we're talking about the pending alliance will be profitable for your organization, get us through this audit...type of third party audit.

Playing these situations to your fullest abilities will not only increase the profitability of your business, it will also result in a tightened down security posture for your company.  I know, audits tend to cause headaches, neck pain as well as stress and the related "burn out" syndrome. But, I say expand your horizons, take a look at the big picture.  How close are you to the ISO standards?  What are those little pet projects that are curtailed by cultural issues which require C-level buy-in?  This may be the straw that increases security in your environment.  You may even get your pet project going again after frustrating funding delays.

I seem to be going through my fair share of these lately and have a few pieces of advice for those facing this same reality.

  1. Stay calm and be prepared to the best of your ability.
  2. Provide the auditor with a hard and soft copy of your IT Security policy, hopefully one based on Internationally agreed standards.
  3. Use post-it flags to mark answers in the policy to any questions provided in advance. Saving the auditor time is a good thing.
  4. Make sure your policies include the approval date and revision histories for each section of policy.
  5. Set up a clean "routine" image workstation for the auditor to verify at their leisure.
  6. Have copies of your Security Awareness Training materials ready.
  7. Give heads up to the collateral departments which will need to provide requested documentation.  Like HR for background checks and Physical Security for access logs. 
  8. Practice accessing your logs from any SEIM or logging device.  Double check logging enabled settings on all critical servers.
  9. Allow the examiner to work in a secured environment away from prying eyes and curious onlookers.
  10. Re-evaluate and study your questionnaire answers from the previous phases of the audit.
  11. Showing your professionalism and your dedication to security will undoubtedly assist in obtaining the vital business alliances required in our global economy.

 Let me know some of your audit survival skills and secrets and I'll update this page with your ideas.

Leave a comment



 Where is James King?


 

Language Translation




 

Other Links:


 Main
 Public Trail Maps
 Archives
 CMS
 About/Contact
 Twitter @BruteForce
 Facebook
 LinkedIn
 Geocaching
 View DGP stats

 

My Audio & Video:


 Flickr
 YouTube
 Pandora

 

Elsewhere:


 ATV Utah
 Our ATV Obsession
 Bogley Outdoor Community
 ATV Escape
 Trish's Cake Shop
 Dennis Udink's Site
 Army Ranger
 Alex's World
 Grizzly Guy
 Adventure World TV
 WeatherCam: UofU
 Delta Bravo Sierra Comics  
 PowerPoint Ranger Comics
 Reversaroller ATV Winch

March 2022

Sun Mon Tue Wed Thu Fri Sat
    1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29 30 31    

Recent Photos

About this Entry

This page contains a single entry by James King published on August 17, 2009 8:08 AM.

Office, Windows get critical patches was the previous entry in this blog.

Adventure World Episode 4 is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.