Truth exists, only falsehood has to be invented.

Georges Braque, 1882–1963

Auditors perform an essential role in protecting the information assets of the organization, which should be embraced versus feared. Many times when an audit is scheduled, whether internally or externally initiated, the response is one of fear of what the auditors will find as gaps in the information security program. Analogous to how many people feel when they are scheduled for their annual performance review, anxiety is almost certain to be a normal response. Why is it that way? The answer is simple: No one likes to criticized for what they have put their best efforts into, and just like the potentially stressful performance ...

Get Information Security Governance Simplified now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.