Skip to Content
The Cybersecurity Manager's Guide
book

The Cybersecurity Manager's Guide

by Todd Barnum
March 2021
Beginner
176 pages
4h 54m
English
O'Reilly Media, Inc.
Content preview from The Cybersecurity Manager's Guide

Chapter 11. Working with the Audit Team

In Chapter 10, I discussed the value of security metrics and which metrics really matter when building your program. Metrics are a valuable tool to convince company management that your efforts are paying off and that the company is getting an ROI from the resources committed to security. The subject of this chapter is working with the audit department.

Your goal in working with this group is to obtain some value from the time spent (or drained) by the audit process. If left unguided, the audit team will spend lots of time on audit endeavors that do not improve the company’s InfoSec posture. Few auditors know much about InfoSec. It’s your job to partner with the audit department and ensure its efforts move the security needle forward.

The Audit Team Needs Your Help to Be Effective in Cybersecurity

Let me start by saying I’m not a fan of the audit department. Why? Because auditors have taught me over the past 20 years that they don’t know how to audit the InfoSec space and rely on external auditors too much for guidance. As a result, much of my time and the InfoSec team’s time with auditors is spent on frivolous and insignificant activities. Without close partnership with the InfoSec team, corporate audit activities are often misguided and ineffective at moving the security needle for the good of the company.

As I mentioned in Chapter 4, relationships are the key to your success, and it’s nowhere truer than with the audit department. At ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Cybersecurity Leadership Demystified

Cybersecurity Leadership Demystified

Dr. Erdal Ozkaya

Publisher Resources

ISBN: 9781492076209Errata Page