Audits
Overview
The Audits component is the core element of the Audit Center module, designed to help organizations plan, conduct, document, and track security audits. This component provides a structured approach to evaluating your security controls, identifying gaps, and implementing improvements to strengthen your security posture.
Security audits are essential for verifying the effectiveness of your security program, demonstrating compliance with regulatory requirements, and identifying opportunities for improvement. The Audits component integrates with other elements of the Audit Center and the broader Risk & Compliance Suite to provide a comprehensive framework for security assessment and continuous improvement.
Key Features
Audit Planning and Management
Audit Scheduling - Plan and schedule internal and external security audits
Audit Scope Definition - Define the boundaries and objectives of each audit
Audit Team Assignment - Designate auditors and subject matter experts
Framework-Based Audits - Conduct audits based on standard frameworks (ISO, NIST, etc.)
Custom Audit Criteria - Create organization-specific audit requirements
Audit Execution
Control Assessment - Evaluate the implementation and effectiveness of security controls
Evidence Collection - Gather and organize documentation to support audit findings
Interview Management - Schedule and document discussions with key personnel
Testing Documentation - Record the results of control testing activities
Observation Tracking - Document issues identified during the audit process
Audit Documentation
Audit Records - Maintain comprehensive documentation of audit activities
Evidence Repository - Store and organize supporting documentation
Audit Trail - Track all actions and decisions during the audit process
Audit Reports - Generate detailed reports of audit results and recommendations
Historical Records - Maintain archives of past audits for reference and comparison
Audit Integration
Finding Management - Link audits to identified issues and observations
Corrective Action Tracking - Connect audits to remediation activities
Control Mapping - Associate audits with specific security controls
Risk Alignment - Relate audit activities to identified security risks
Compliance Mapping - Link audits to regulatory requirements and standards
Getting Started
Accessing the Audits Component
Log in to your AskInfosec account
Navigate to the main dashboard
Select "Audit Center" from the main navigation menu
Click on "Audits" in the submenu
You will be directed to the Audits dashboard
Audits Dashboard
The Audits dashboard provides an overview of your organization's audit activities, including:
Upcoming Audits - Scheduled audits and their status
In-Progress Audits - Audits currently being conducted
Completed Audits - Recently finished audit activities
Audit Calendar - Timeline view of scheduled audits
Audit Statistics - Metrics on audit completion, findings, and remediation
Managing Audits
Creating a New Audit
To set up a new audit:
From the Audits dashboard, click the "New Audit" button
Enter basic audit information:
Audit Name
Description
Start and End Dates
Audit Owner
Audit Team Members
Select the audit type:
Framework-based (e.g., ISO 27001, NIST CSF)
Control-specific (selected controls only)
If framework-based, select the relevant framework
Click "Create" to set up the audit
You will be directed to the audit details page for further configuration
Audit Details
The audit details page contains comprehensive information about a specific audit:
Basic Information - Name, description, dates, and ownership
Audit Scope - Frameworks, controls, or systems being evaluated
Audit Team - Individuals involved in conducting the audit
Audit Status - Current state of the audit process
Related Items - Findings, requests, and corrective actions
Audit Status Management
Audits typically follow this lifecycle:
Planned - Initially created, not yet started
In Progress - Audit activities have begun
Under Review - Audit completed, results being reviewed
Completed - Audit finalized, including all documentation
Archived - Historical audit preserved for reference
To update an audit's status:
Navigate to the audit details page
Click "Update Status"
Select the new status
Provide comments explaining the status change
Save the status update
Conducting Audits
Audit Preparation
Before beginning an audit:
Review the audit scope and objectives
Gather relevant documentation:
Security policies and procedures
Previous audit reports
Control documentation
Compliance requirements
Prepare an audit plan:
Schedule of activities
Required resources
Stakeholder involvement
Evidence collection methods
Notify relevant stakeholders
Conduct a kickoff meeting to explain the audit process
Audit Execution
To conduct an audit:
Navigate to the audit details page
For each control or requirement in scope:
Review the control description and requirements
Collect and evaluate evidence of implementation
Document observations and test results
Determine compliance status
Create findings for identified issues
Update the audit status as you progress
Document all activities in the audit record
Framework-Based Audits
When conducting an audit based on a standard framework:
Navigate to the audit details page
Select the "Controls" tab
View the list of framework controls in scope
For each control:
Review the control requirements
Assess implementation status
Document evidence and observations
Assign a compliance rating
Track overall framework compliance
Generate a compliance report
Control-Specific Audits
When conducting an audit of selected controls:
Navigate to the audit details page
Select the "Controls" tab
Click "Add Controls" to select specific controls for assessment
For each selected control:
Review the control requirements
Assess implementation status
Document evidence and observations
Assign a compliance rating
Track control-specific compliance
Generate a targeted assessment report
Managing Audit Requests
During an audit, you may need to request information or actions from various stakeholders:
From the audit details page, click "New Request"
Enter request details:
Request Name
Description
Assigned To
Due Date
Save the request
Track request status and follow up as needed
Close the request when completed
Audit Evidence Management
Adding Evidence to Audits
To document control implementation:
Navigate to the audit details page
Select the "Evidence" tab
Click "Add Evidence"
Choose the evidence type:
Document upload
Link to existing document
Screenshot
Text description
External reference
Provide a description explaining how the evidence relates to the audit
Upload or link the evidence
Save the evidence record
Managing Evidence
To organize and maintain audit evidence:
Navigate to the audit details page
Select the "Evidence" tab
View all evidence associated with the audit
Filter evidence by type, date, or control
Update or replace outdated evidence
Remove irrelevant or obsolete evidence
Evidence Review
During audit assessment, review evidence for:
Relevance - Does the evidence directly relate to the control?
Completeness - Does it fully demonstrate compliance?
Currency - Is the evidence up-to-date?
Authenticity - Is the evidence reliable and trustworthy?
Sufficiency - Is there enough evidence to support compliance?
Audit Findings and Follow-up
Creating Findings
To document issues identified during an audit:
From the audit details page, click "New Finding"
Enter finding details:
Finding Name
Description
Severity (High, Medium, Low)
Category
Assigned To
Link the finding to relevant controls or requirements
Save the finding
The finding will appear in the Findings tab of the audit
Importing Findings
To import multiple findings from an external source:
From the audit details page, click "Import Findings"
Select the import format (CSV, Excel)
Upload the file containing finding information
Map the file columns to the required finding fields
Review the imported findings
Confirm the import to add the findings to the audit
Creating Corrective Actions
To define steps for addressing audit findings:
From the finding details page, click "New Corrective Action"
Enter corrective action details:
Action Name
Description
Root Cause
Assigned To
Due Date
Priority
Save the corrective action
The action will appear in the Corrective Actions tab of the finding
Audit Reporting
Generating Audit Reports
To create a comprehensive report of audit activities:
Navigate to the audit details page
Click "Generate Report"
Select the report type:
Executive Summary
Detailed Audit Report
Findings Report
Compliance Status Report
Choose the report format (PDF, Excel, Word)
Generate the report
Download or share the report as needed
Audit Dashboards
To visualize audit status and results:
Navigate to the Audits dashboard
View the standard dashboards:
Audit Status Overview
Finding Distribution
Corrective Action Progress
Compliance Heatmap
Filter dashboards by date range, audit type, or department
Export dashboard visualizations for presentations or reports
Audit Integration
Control Management Integration
The Audits component integrates with Control Management:
Select controls from your control inventory for audit scope
Update control assessments based on audit results
Link findings to specific controls for targeted remediation
Track control effectiveness through audit history
Risk Management Integration
The Audits component integrates with Risk Management:
Consider high-priority risks when planning audits
Create or update risks based on audit findings
Link findings to existing risks for comprehensive tracking
Use audit results to refine risk assessments
Policy Management Integration
The Audits component integrates with Policy Management:
Verify policy implementation through audit activities
Link findings to policy gaps or non-compliance
Update policies based on audit recommendations
Demonstrate policy effectiveness through audit results
Best Practices
Audit Planning
Define clear objectives - Establish specific goals for each audit
Right-size the scope - Ensure the audit is manageable and focused
Involve stakeholders - Engage affected teams in planning
Prepare adequately - Gather necessary information before starting
Communicate effectively - Ensure all parties understand the process
Audit Execution
Follow a structured approach - Use consistent methodology
Document thoroughly - Maintain detailed records of all activities
Remain objective - Base findings on evidence, not assumptions
Be respectful - Conduct audits professionally and collaboratively
Verify information - Confirm observations through multiple sources
Audit Documentation
Be comprehensive - Include all relevant information
Maintain clarity - Ensure documentation is easy to understand
Use standardized formats - Apply consistent templates and structures
Preserve evidence - Securely store all supporting documentation
Enable traceability - Create clear links between observations and conclusions
Audit Follow-up
Prioritize findings - Focus on high-risk issues first
Assign clear ownership - Ensure responsibility for remediation
Set realistic deadlines - Allow adequate time for corrective actions
Verify implementation - Confirm that issues have been addressed
Learn from results - Use audit outcomes to improve processes
Troubleshooting
Common Issues
Scope creep - Keep audits focused on defined objectives
Insufficient evidence - Ensure adequate documentation is collected
Delayed responses - Follow up on information requests promptly
Inconsistent assessments - Use standardized evaluation criteria
Incomplete documentation - Verify all audit activities are recorded
Getting Support
If you encounter issues with the Audits component:
Check the in-app help documentation
Contact your organization's system administrator
Submit a support ticket through the AskInfosec support portal
Conclusion
Effective audit management is essential for verifying the effectiveness of your security program, demonstrating compliance with regulatory requirements, and identifying opportunities for improvement. The Audits component provides the tools and structure needed to plan, conduct, document, and track security audits in a consistent, comprehensive manner.
By following the processes outlined in this guide, you can establish a robust audit program that helps your organization identify security gaps, implement improvements, and demonstrate due diligence in protecting your information assets.
Last updated