Instruction
When developing an audit plan, we must first identify the items to be audited. Each audit looks at controls that are derived from internal and external sources. Controls that are implemented and managed locally within the organization and the enterprise are internal controls.
For services provided by outside vendors or third parties, compliance is usually managed through the use of service-level agreements (SLA). An SLA is a contractual agreement specifying that the vendor or third party will adhere to a predefined set of requirements. These requirements should fall within the organization's compliance requirements. The services an organization receives from an external agency are known as inherited controls.
A key component in developing an audit plan is to identify the organizational controls that are internal and inherited. As an auditor, you are responsible to ensure that are both internal and inherited controls are within compliance of accrediting the system. Those items not meeting SLA requirements that may or may not be injecting any level of risk into accreditation should be reported to the client or contracting official within your organization.
As you have learned in your reading and lessons, an audit plan consists of various components. A fundamental aspect of any audit is to clearly define what will be audited. When that’s known, the auditor can review those items to determine which controls are internal and which are inherited so the right resources can be assigned to validating those controls.
Instructions
Download the Worksheet: Creating an Audit Plan [DOCX].
Review the following scenario, and in Table 1: Internal/Inherited Controls, determine if the control is internal or inherited:
XYZ Corporation has retained you to audit their enterprise and validate their compliance requirements.
XYZ Corporation has a staff of 200 employees and an IT staff of three personnel.
Internal to XYZ Corp, the organization has a server room that houses network storage for proprietary data, an application server to manage applications and licenses, a Web server that hosts the company’s internal and external websites, hardware firewalls, and security appliances to manage and protect inbound and outbound services.
The organization has contracted Python LLC to provide email, VoIP, SaaS and cloud storage services for nonproprietary data for XYZ Corp.
The audit and auditor are also auditable and considered a control within the NIST framework. In Table 2: Control Numbers and Assessment Objectives, referring to the NIST SP-53 and 53A, Audit and Accountability Policy and Procedures from NIST Special Publication 800-53A [PDF]:
In the Control Number column, enter the control numbers for the family.
In the Definition column, identify and discuss the assessment objective.
In the Comments column, explain why you chose that control to fit the scenario.
When an auditor develops an audit plan, the size or scope of the audit must be defined so redundant audits are avoided and that time can be applied to the necessary controls. In Table 3: Auditable Domains, list the seven domains that are auditable.