Audit Icon

Audit

Subscribe to our Compliance and Regulation YouTube Playlist.

Audits are one of those tasks that can be helpful yet intimidating. From a personal standpoint, I've always been open to audits as they allowed for a third party to "evaluate" something, which then allowed for requesting a budget increase.

As audits go, there are a few different types...keep reading below.


Visit our online store to purchase training and services


Internal audits are official or unofficial assessments of a company's internal functions, generally conducted by employees with auditing experience.  This is also known as a first-party audit.  Please also see the last paragraph relating to management reviews and Internal ISMS audits.  Read our one-pager on Internal Audits here.  

External audits are official or unofficial assessments of a company conducted by a third-party audit firm.  Generally, these third-party audit companies employ persons who hold an auditor certification of some sort.  Examples include ISO 27001, PCI, HIPAA, or CMMC.

Then we have another form of external audit: an audit function applied to a third party, most likely a vendor providing services to a client company.  The whole purpose of this type of audit is to ensure that any vendors providing services to a client company are safe to do business with.

As it relates to audits, it's important that the audit scope be determined before the audit and fully agreed upon by the audit team and the auditee.  Otherwise, a never-ending audit may occur.  From a tactical standpoint, the auditee is also advised to keep the audit scope to the smallest possible footprint, as this will keep costs down and reduce effort overall.

Lastly, and extremely important, are the management reviews and internal ISMS audits.  If you are seeking anything relating to ISO (specifically ISO 27001), then this must be performed and be able to be proven.  This relates to ISO 27006 section 9.5.2, which states: "Certification shall not be granted to the client until there is sufficient evidence to demonstrate that arrangements for management reviews and internal ISMS audits have been implemented, are effective and will be maintained."

Need to validate the security of your suppliers?  Our Prosikon platform can help reduce your risk.

Check out our platforms that help reduce effort and risk

Arrakis has built over several months numerous platforms that can help reduce risk.  Read more here and those platforms are listed below.

- Compliance Chatbot - a free chatbot relating to compliance, cybersecurity, and privacy.
- Prosikon - A feature rich vendor due diligence platform to help increase visibility and provide more information for safer decisions.  Read more here.
- PolicyForge - Build out your policies based on the regulatory environment you care about.  Policy and Procedure Templates are included as well as control mapping.  Read more here.
- Fortuna Risk Compass - Feature rich risk assessment platform that helps you visualize risk and cost better.  Numerous graphical displays and ability to export risks to Prothesis.  Read more here.
- Prothesis PoAM Builder - Build your PoAMs to prove you are mitigating risk and demonstrating maturity.  Expands on Fortuna risks and demonstrates the "why" on the need for PoAMs.  Read more here.
- Mutina SecurePath - Construct your SSPs to meet CMMC, or other frameworks, to provide assurance to external parties.  SSPs are required for CMMC compliance.  Read more here.
- CyberPrep Test Engine - A subscription based practice test platform covering 50+ certifications.  Designed to be more difficult than the actual test to increase certification chances.

Regardless of the platforms, Arrakis suggests contracting professional consultation when seeking certification or compliance.


Contact us by filling out this form - Contact Us


Unlocking Audit Success with Arrakis Consulting

Mastering SOC2 compliance with Arrakis Consulting

Simplify your next audit with Arrakis Consulting

Achieve 27001 certification with Arrakis Consulting

Arrakis can help you with your audit needs and also act as a trusted agent or advisory during your audit activities. If you need help, give us a call.

We are masters at these frameworks and many more.

Our membership in professional organizations

Contact Us