Knowledgebase

Preparing a Database for an Audit Print

  • 0

Demonstrating control.

WHAT AUDITORS TYPICALLY ASK ABOUT

Who has access, and how it is granted and removed How changes are controlled Whether backups exist and are tested Whether sensitive data is protected Whether activity is logged How long data is retained

WHAT TO PREPARE

A list of accounts and their privileges Evidence of access reviews Migration history Backup and restore test records Retention policy and evidence of enforcement

WHY EVIDENCE RATHER THAN ASSERTION

Compliance is demonstrated, not claimed.

WHAT MAKES EVIDENCE CREDIBLE

Being produced by the process itself rather than assembled beforehand.

WHAT TO AUTOMATE

Collection of that evidence.

WHAT COMMONLY FAILS AN AUDIT

Shared accounts No record of access reviews Backups never tested Production data in development Retention policy that exists on paper only

WHAT TO FIX FIRST

Shared accounts, which undermine everything else.

WHY

Without attribution, no other control can be demonstrated.

WHAT TO DOCUMENT

The controls, and how each is enforced.

WHAT TO BE HONEST ABOUT

Gaps.

WHY

Discovered gaps are far worse than disclosed ones.

WHAT TO TAKE ADVICE ON

Which framework actually applies to you.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot