Cybersecurity Audits, Frameworks, and Controls

Ravi Das · Auerbach Publications eBooks · 2021

This chapter covers the concept of what a Cybersecurity Audit is. Cybersecurity audits are performed by third-party vendors in order to eliminate any conflicts of interest. They can also be administered by an in-house team as long as they act independently of their parent organization. The chapter explores the various Cybersecurity Control Frameworks that are available, and from there, do a deeper dive into the individual Cybersecurity Controls that are available today. Proper actions can then be taken to make sure that all appropriate mechanisms are thus put in place, including the Controls to remediate the weaknesses and vulnerabilities that have been discovered as a result of doing the Cyber Audit. The Cyber Audit management team maintains a full oversight in terms of the reporting of the deficiencies, especially as it relates to the Controls. The ISO entity actually has its roots going all the way back to 1947, and is actually independent and neutral from other Cybersecurity-related Framework organizations.

Read the paper · More papers on PaperTik