Internal Audit and Assessment

Internal audits and assessments evaluate controls, verify compliance, uncover weaknesses, and guide improvements.

7 slides · 5 min read · Domain 6

Slide 1

The purpose of an internal assessment is to determine whether the security controls meet the organization's risk expectations.

Internal assessment results may also assist the organization in improving the efficiency of operations, demonstrating an organizational commitment to good cybersecurity practice and in preparation for external audits.

In many cases, this internal assessment is undertaken by the organization itself, rather than engaging a private organization. Self-assessment requires organizational rigor and a willingness to seek answers to hard questions. Many organizations that have been breached find that their internal culture did not encourage rigorous introspection of organizational activities and processes.

Whether the assessment is performed by the organization or by a third party chartered by management, the organization's culture and management commitment will determine the value of the assessment process.

The process for internal assessment will vary between organizations, but successful organizations have a consistent methodology for performing their internal assessments. The internal assessment generally includes four steps: chartering, testing, reporting, and remediating.

Chartering

Management commitment starts the assessment process. Organizational management must sponsor and resource the assessment activities, which may require financial, technical, or organizational resources to execute. The people performing the assessment are unlikely to have the authority within the organization to get cooperation and resources across the organization without appropriate management support.

Scoping the assessment is also the responsibility of management. Previous risk assessments, changes in technology, organizational structure, and roles or partnerships may help in determining the scope of the assessment. Regardless of the reason, management must determine the depth and breadth of the assessment activities, schedule for the work, how the assessment will be conducted, reporting format for the results, and determination of who will perform the work. Scoping is essential to prioritization of effort and efficient conduct of the assessment.

Stakeholder engagement prior to the initiation of the assessment helps ensure the assessment does not interrupt operational activities and that management's intent for the work will be achieved. In many cases, the stakeholders will help shape the conduct of the assessment, bringing unique perspectives and knowledge to the assessment activities. Developing a stakeholder management plan to identify stakeholders, properly convey the assessment activities, gather input, and communicate the results will greatly assist the assessment's conduct.

Risk assessment must be performed throughout the assessment process to ensure that the risks associated with the conduct of the assessment are properly identified and controlled.

Operational disruptions, inappropriate communication of results, and improper scoping are only a few of the potential negative consequences that should be considered in the risk assessment process.

Testing

Once the assessment's scope and timing are established, the conduct of the work can commence.

Typically, the scope will address physical, technical, and administrative controls, including the people, processes, and technologies used to support the business. As part of the assessment process, many tools may be used. The vulnerability assessment suggests areas where weaknesses may exist. A vulnerability assessment may take advantage of network- or clientscanning tools or may be performed as part of a physical security evaluation of the environment. Once vulnerabilities have been identified, risk-based decisions can be made as to the appropriate response, which might include further investigation or applying control to the vulnerability.

Penetration testing approaches the evaluation of system security from the perspective of an adversary. Unlike a vulnerability assessment, a penetration test does not simply identify likely weaknesses, but tries to exploit the potential weakness. These are among the techniques that will be discussed in later subdomains.

Reporting

The results of the internal assessment can be valuable for a variety of purposes.

The report may act as a benchmark for tracking control performance, as a tool to inform corrective activities or continuous improvement processes, or as an artifact in support of external audit and assessment activities.

Different audiences may require different levels of detail, and the reporting of the results must be sensitive to the information needs of the various stakeholders.

The timing and format of the reporting will be performed as specified by management in the chartering process. The reporting format may be a formal assessment report or an informal memorandum, or it may be used to feed a management dashboard. Regardless of the format, the disclosure of results is the responsibility of management.

The artifacts collected as part of the assessment also require protection from alteration or inappropriate disclosure. Information that shows where controls are, and are not, effective is sensitive; the reporting processes should ensure the information is properly safeguarded throughout the assessment process and maintained in accordance with the organization's records management practice.

Remediating

The results of the internal assessment may identify areas where corrective action or improvement is warranted.

Remediation activities should proceed as defined by the organization's practice, but typically will include some way to associate the results of the assessment with the corrective activity. In the U.S. federal government, the Plan of Action and Milestones (POA&M) provides an example of a corrective process that can be applied to identified weaknesses.

A POA&M, as described in NIST SP 80037 on the Risk Management Framework, acts as a blueprint for addressing security deficiencies and vulnerabilities identified within an information system. It outlines the specific steps an organization needs to take to correct these issues and improve its overall security posture.

The POA&M, known by a variety of names outside U.S. government circles, tracks the weakness and the proposed remediation, necessary resources, and schedule by which the work will be completed.

Internal assessment is essential to ensuring the organization's controls are meeting management's expectations. It is the starting point for improving an organization's security posture and requires a consistent commitment by management to ensure its success.

Test this domain