© Raymond Pompon 2016

Raymond Pompon, IT Security Risk Control Management, 10.1007/978-1-4842-2140-2_24

24. Post Audit Improvement

Raymond Pompon

(1)Seattle, Washington, USA

Everything flows and nothing abides. Everything gives way and nothing stays fixed.

—Heraclitus

So now you’re done. Your security program is up and running, you’ve made it through your audit, and everyone is happy. Take a vacation and rest. You can forget about security, forever. Yeah, you know I’m kidding. As long as there are threats in the world, the security team can never close their eyes.

Now that you’ve seen how your security architecture has stood up against adversity and auditors, it’s time to tackle the final step of the Plan-Do-Check-ActCycle. This is when the ISMS ...

Get IT Security Risk Control Management: An Audit Preparation Plan now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.