Audit Center
Overview
The Audit Center module is a core component of the Risk & Compliance Suite, designed to help organizations plan, conduct, document, and track security audits. This module provides a structured approach to evaluating your security controls, identifying gaps, and implementing improvements to strengthen your security posture.
Security audits are essential for verifying the effectiveness of your security program, demonstrating compliance with regulatory requirements, and identifying opportunities for improvement. The Audit Center module integrates with other components of the Risk & Compliance Suite to provide a comprehensive framework for security assessment and continuous improvement.
Key Features
Audit Planning and Management
Audit Scheduling - Plan and schedule internal and external security audits
Audit Scope Definition - Define the boundaries and objectives of each audit
Audit Team Assignment - Designate auditors and subject matter experts
Framework-Based Audits - Conduct audits based on standard frameworks (ISO, NIST, etc.)
Custom Audit Criteria - Create organization-specific audit requirements
Audit Execution
Control Assessment - Evaluate the implementation and effectiveness of security controls
Evidence Collection - Gather and organize documentation to support audit findings
Interview Management - Schedule and document discussions with key personnel
Testing Documentation - Record the results of control testing activities
Observation Tracking - Document issues identified during the audit process
Finding Management
Finding Documentation - Record and categorize issues identified during audits
Finding Classification - Categorize findings by severity, type, and affected area
Root Cause Analysis - Identify underlying causes of security deficiencies
Finding Assignment - Designate responsibility for addressing each finding
Finding Status Tracking - Monitor the resolution of identified issues
Corrective Action Management
Corrective Action Planning - Develop specific steps to address audit findings
Action Assignment - Designate responsibility for implementing corrective actions
Due Date Tracking - Monitor deadlines for completing remediation activities
Implementation Verification - Confirm that corrective actions have been implemented
Effectiveness Assessment - Evaluate whether actions have resolved the underlying issues
Audit Reporting
Audit Summary Reports - Generate comprehensive documentation of audit activities
Finding Reports - Create detailed reports of identified issues and recommendations
Compliance Status Reports - Document adherence to regulatory requirements
Executive Dashboards - Provide high-level insights for leadership
Historical Trending - Track audit results and improvements over time
Getting Started
Accessing the Audit Center
Log in to your AskInfosec account
Navigate to the main dashboard
Select "Audit Center" from the main navigation menu
You will be directed to the Audit Center dashboard
Audit Center Dashboard
The Audit Center dashboard provides an overview of your organization's audit activities, including:
Upcoming Audits - Scheduled audits and their status
Recent Findings - Latest issues identified during audits
Corrective Actions - Status of remediation activities
Compliance Status - Overview of adherence to key requirements
Audit History - Record of completed audits and their results
Managing Audits
Creating a New Audit
To set up a new audit:
From the Audit Center dashboard, click the "New Audit" button
Enter basic audit information:
Audit Name
Description
Start and End Dates
Audit Owner
Audit Team Members
Select the audit type:
Framework-based (e.g., ISO 27001, NIST CSF)
Control-specific (selected controls only)
If framework-based, select the relevant framework
Click "Create" to set up the audit
You will be directed to the audit details page for further configuration
Audit Details
The audit details page contains comprehensive information about a specific audit:
Basic Information - Name, description, dates, and ownership
Audit Scope - Frameworks, controls, or systems being evaluated
Audit Team - Individuals involved in conducting the audit
Audit Status - Current state of the audit process
Related Items - Findings, requests, and corrective actions
Audit Execution
To conduct an audit:
Navigate to the audit details page
Review the audit scope and objectives
For each control or requirement:
Review the control description and requirements
Collect and evaluate evidence of implementation
Document observations and test results
Determine compliance status
Create findings for identified issues
Update the audit status as you progress
Complete the audit by generating a summary report
Managing Audit Requests
During an audit, you may need to request information or actions from various stakeholders:
From the audit details page, click "New Request"
Enter request details:
Request Name
Description
Assigned To
Due Date
Save the request
Track request status and follow up as needed
Close the request when completed
Managing Findings
Creating a New Finding
To document an issue identified during an audit:
From the audit details page, click "New Finding"
Enter finding details:
Finding Name
Description
Severity (High, Medium, Low)
Category
Assigned To
Link the finding to relevant controls or requirements
Save the finding
The finding will appear in the Findings tab of the audit
Finding Details
The finding details page contains comprehensive information about a specific issue:
Basic Information - Name, description, severity, and category
Assignment - Individuals responsible for addressing the finding
Status - Current state of the finding resolution process
Related Items - Associated controls, policies, and corrective actions
Attachments - Supporting documentation and evidence
Importing Findings
To import multiple findings from an external source:
From the audit details page, click "Import Findings"
Select the import format (CSV, Excel)
Upload the file containing finding information
Map the file columns to the required finding fields
Review the imported findings
Confirm the import to add the findings to the audit
Managing Corrective Actions
Creating a Corrective Action
To define steps for addressing a finding:
From the finding details page, click "New Corrective Action"
Enter corrective action details:
Action Name
Description
Root Cause
Assigned To
Due Date
Priority
Save the corrective action
The action will appear in the Corrective Actions tab of the finding
Corrective Action Details
The corrective action details page contains comprehensive information about a specific remediation activity:
Basic Information - Name, description, and root cause
Assignment - Individuals responsible for implementing the action
Timeline - Due date and detection date
Status - Current state of the implementation process
Related Items - Associated findings, controls, and evidence
Tracking Corrective Action Progress
To monitor the implementation of corrective actions:
Navigate to the Corrective Actions section of the Audit Center
View the status of all corrective actions
Filter by status, priority, or assignment
Update action status as implementation progresses
Verify completion by reviewing evidence and testing results
Audit Evidence Management
Adding Evidence to Audits
To document control implementation:
Navigate to the audit details page
Select the "Evidence" tab
Click "Add Evidence"
Choose the evidence type:
Document upload
Link to existing document
Screenshot
Text description
External reference
Provide a description explaining how the evidence relates to the audit
Upload or link the evidence
Save the evidence record
Managing Evidence
To organize and maintain audit evidence:
Navigate to the audit details page
Select the "Evidence" tab
View all evidence associated with the audit
Filter evidence by type, date, or control
Update or replace outdated evidence
Remove irrelevant or obsolete evidence
Evidence Review
During audit assessment, review evidence for:
Relevance - Does the evidence directly relate to the control?
Completeness - Does it fully demonstrate compliance?
Currency - Is the evidence up-to-date?
Authenticity - Is the evidence reliable and trustworthy?
Sufficiency - Is there enough evidence to support compliance?
Audit Reporting
Generating Audit Reports
To create a comprehensive report of audit activities:
Navigate to the audit details page
Click "Generate Report"
Select the report type:
Executive Summary
Detailed Audit Report
Findings Report
Compliance Status Report
Choose the report format (PDF, Excel, Word)
Generate the report
Download or share the report as needed
Audit Dashboards
To visualize audit status and results:
Navigate to the Audit Center dashboard
View the standard dashboards:
Audit Status Overview
Finding Distribution
Corrective Action Progress
Compliance Heatmap
Filter dashboards by date range, audit type, or department
Export dashboard visualizations for presentations or reports
Integration with Other Modules
Control Management Integration
The Audit Center integrates with Control Management:
Select controls from your control inventory for audit scope
Update control assessments based on audit results
Link findings to specific controls for targeted remediation
Track control effectiveness through audit history
Risk Management Integration
The Audit Center integrates with Risk Management:
Consider high-priority risks when planning audits
Create or update risks based on audit findings
Link findings to existing risks for comprehensive tracking
Use audit results to refine risk assessments
Policy Management Integration
The Audit Center integrates with Policy Management:
Verify policy implementation through audit activities
Link findings to policy gaps or non-compliance
Update policies based on audit recommendations
Demonstrate policy effectiveness through audit results
Best Practices
Audit Planning
Define clear objectives - Establish specific goals for each audit
Right-size the scope - Ensure the audit is manageable and focused
Involve stakeholders - Engage affected teams in planning
Prepare adequately - Gather necessary information before starting
Communicate effectively - Ensure all parties understand the process
Audit Execution
Follow a structured approach - Use consistent methodology
Document thoroughly - Maintain detailed records of all activities
Remain objective - Base findings on evidence, not assumptions
Be respectful - Conduct audits professionally and collaboratively
Verify information - Confirm observations through multiple sources
Finding Management
Be specific - Clearly describe each issue and its impact
Prioritize effectively - Focus on high-risk findings first
Assign clear ownership - Ensure responsibility for resolution
Set realistic deadlines - Allow adequate time for remediation
Follow up consistently - Track progress and verify completion
Corrective Action Management
Address root causes - Focus on underlying issues, not just symptoms
Define measurable outcomes - Establish clear success criteria
Allocate sufficient resources - Ensure teams can implement actions
Monitor progress - Track implementation status regularly
Verify effectiveness - Confirm that actions resolve the findings
Troubleshooting
Common Issues
Scope creep - Keep audits focused on defined objectives
Insufficient evidence - Ensure adequate documentation is collected
Delayed responses - Follow up on information requests promptly
Inconsistent assessments - Use standardized evaluation criteria
Overdue corrective actions - Escalate when remediation is delayed
Getting Support
If you encounter issues with the Audit Center module:
Check the in-app help documentation
Contact your organization's system administrator
Submit a support ticket through the AskInfosec support portal
Conclusion
Effective audit management is essential for verifying the effectiveness of your security program, demonstrating compliance with regulatory requirements, and identifying opportunities for improvement. The Audit Center module provides the tools and structure needed to plan, conduct, document, and track security audits in a consistent, comprehensive manner.
By following the processes outlined in this guide, you can establish a robust audit program that helps your organization identify security gaps, implement improvements, and demonstrate due diligence in protecting your information assets.
Last updated