Cybersecurity and Privacy Controls
Robert R. Moeller · 2012
This chapter discusses internal audit cybersecurity and privacy controls from two broad perspectives. The first focus area is the various cybersecurity and privacy concerns that internal auditors should consider in their reviews of information technology (IT)-based systems and processes. The second cybersecurity and privacy controls focus area includes internal audit's internal procedures. The chapter suggests some best practices for an internal audit function and presents a discussion of the payment card industry data security standard (PCI-DSS), a guideline developed by major credit card companies, such as Visa and American Express, to help enterprises that process card payments prevent credit card fraud and to provide some protection from various credit security vulnerabilities and threats.