
Information System Development, Acquisition, and Maintenance ◾ 253
Audit
Larger organizations are typically subject to audit requirements and many also have
an internal audit group. From a security perspective, audits can be great opportuni-
ties to highlight and get support for security issues that may be present in an orga-
nization. Internal audit and information security often have very similar goals and
can work together to help the organization achieve stronger controls.
Managing Information Security Concerns in a Maturing System
As the system matures, there will be ongoing information security concerns.
Incidents will need to be managed, ...