Identifying Minimum Acceptable Level of Risk and Appropriate Security Baseline DefinitionsOrganization-WideSeven Domains of a Typical IT InfrastructureGap Analysis for the Seven DomainsIdentifying All Documented IT Security Policies, Standards, Procedures, and GuidelinesConducting the Audit in a Layered FashionPerforming a Security Assessment for the Entire IT Infrastructure and Individual DomainsIncorporating the Security Assessment Into the Overall Audit Validating Compliance ProcessUsing Audit Tools to Organize Data Capture—CAATTs, Checklists, SpreadsheetsInvestigating the Use of Automated Audit Reporting Tools and MethodologiesReviewing Configurations and Implementations in Compliance with Defined IT Security Policies, Standards, Procedures, and GuidelinesPerforming Testing and Monitoring to Verify and Validate Proper Configuration and Implementation of Security Controls and CountermeasuresIdentifying Common Problems or Issues When Conducting an IT Infrastructure AuditValidating Security Operations and Administration Roles, Responsibilities, and Accountabilities Throughout the IT InfrastructureCHAPTER SUMMARYKEY CONCEPTS AND TERMSCHAPTER 6 ASSESSMENTENDNOTES