Chapter 11. Working with the Audit Team

In Chapter 10, I discussed the value of security metrics and which metrics really matter when building your program. Metrics are a valuable tool to convince company management that your efforts are paying off and that the company is getting an ROI from the resources committed to security. The subject of this chapter is working with the audit department.

Your goal in working with this group is to obtain some value from the time spent (or drained) by the audit process. If left unguided, the audit team will spend lots of time on audit endeavors that do not improve the company’s InfoSec posture. Few auditors know much about InfoSec. It’s your job to partner with the audit department and ensure its efforts move the security needle forward.

The Audit Team Needs Your Help to Be Effective in Cybersecurity

Let me start by saying I’m not a fan of the audit department. Why? Because auditors have taught me over the past 20 years that they don’t know how to audit the InfoSec space and rely on external auditors too much for guidance. As a result, much of my time and the InfoSec team’s time with auditors is spent on frivolous and insignificant activities. Without close partnership with the InfoSec team, corporate audit activities are often misguided and ineffective at moving the security needle for the good of the company.

As I mentioned in Chapter 4, relationships are the key to your success, and it’s nowhere truer than with the audit department. At ...

Get The Cybersecurity Manager's Guide now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.