Demonstrating control.
WHAT AUDITORS TYPICALLY ASK ABOUT
Who has access, and how it is granted and removed How changes are controlled Whether backups exist and are tested Whether sensitive data is protected Whether activity is logged How long data is retained
WHAT TO PREPARE
A list of accounts and their privileges Evidence of access reviews Migration history Backup and restore test records Retention policy and evidence of enforcement
WHY EVIDENCE RATHER THAN ASSERTION
Compliance is demonstrated, not claimed.
WHAT MAKES EVIDENCE CREDIBLE
Being produced by the process itself rather than assembled beforehand.
WHAT TO AUTOMATE
Collection of that evidence.
WHAT COMMONLY FAILS AN AUDIT
Shared accounts No record of access reviews Backups never tested Production data in development Retention policy that exists on paper only
WHAT TO FIX FIRST
Shared accounts, which undermine everything else.
WHY
Without attribution, no other control can be demonstrated.
WHAT TO DOCUMENT
The controls, and how each is enforced.
WHAT TO BE HONEST ABOUT
Gaps.
WHY
Discovered gaps are far worse than disclosed ones.
WHAT TO TAKE ADVICE ON
Which framework actually applies to you.