IT audit as a component of security assessment - we provide an audit checklist

02 października 2019

In one of Netflix's latest productions titled "The Great Hack," which addresses the now-famous Cambridge Analytica scandal, a particularly interesting statement was made indicating that recently, the value of personal data worldwide has surpassed the value of oil (sic!).

Importantly, the processing of the vast majority of them takes place in broadly understood information systems. The significance of personal data is further evidenced by the immense interest it attracts from cybercriminals.

Consequently, the threat of hacking attacks is increasing, with numerous cases (and their serious consequences) being reported by global media almost every day.

How to mitigate the risk?

On one hand, the unlimited reach of the internet, as well as the global dispersion of online service providers, means that we lose control over our data and how it may be used. On the other hand, the fate of data processed within organizations is equally important. Ensuring the security of all information held by a company is not one of the simplest processes and requires undertaking a series of actions.

Audit Checklist
We provide a control audit checklist related to office equipment.
Download

 In light of the above, the comprehensive preparation of an organization consists of several components, such as, among others, developing documentation, training employees, adapting personal data processing processes, and conducting audits. Today, we would like to draw particular attention to the last of the mentioned elements, which allows for examining and assessing the state of the internal IT infrastructure and the security measures applied in this area, without which it is impossible to take further steps towards achieving the aforementioned goals. Areas of IT resources that should be subject to mandatory audit control include, among others, network infrastructure, office equipment, applications, and websites.

What are the benefits of an IT audit?

It should be emphasized that conducting an audit within an organization is the most effective instrument through which the data controller can fulfill its obligations arising from Article 32 of the GDPR. In light of the cited provision: “Taking into account the state of technical knowledge, the cost of implementation, and the nature, scope, context, and purposes of processing (...), the data controller and the data processor implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including, where appropriate: (...) regular testing, measuring, and evaluating the effectiveness of technical and organizational measures to ensure the security of processing.” It is therefore undeniable that it is precisely through a professionally conducted audit that these obligations can be most fully realized.

GDPR in IT

It is worth mentioning that a report is prepared for each audit conducted by a professional entity. Its content includes an assessment of the security status resulting from the factual state established during the audit. However, it should be emphasized that the audit is not limited to making the indicated assessment. The content of the post-audit report includes (and may primarily consist of) recommendations and proposals for specific solutions and improvements that allow for an increase in the level of security in IT systems, while simultaneously minimizing risks associated with the processing of personal data within the organization.

The tool proposed below by the DPO 24 – the audit checklist allows for a preliminary, self-assessment of the extent to which the organization's IT ensures its security and in which areas improvements are required. However, there is no doubt that the most comprehensive benefits for the entity can be obtained through a professional audit conducted by experts experienced in this field.

FREE

10 Principles of Secure IT Environment Management

Watch the webinar

IT Area in Compliance with GDPR

The presented list serves as a preview and simultaneously the premiere part of a series of articles addressing various issues in the field of IT. Through these publications, seasoned practitioners in IT security will elucidate the essential matters necessary for adapting organizations to the requirements of the GDPR. Along with accessible explanations and practical tips, we also offer ready-made tools and document templates that you will be able to use at various stages of modeling the IT infrastructure within your organization.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.