This tool is used to conduct security audits to validate the compliance of information technology and the organisation to the following legislation and standards:
- ISO 27002 (ISO 17799)
- US's Sarbanes-Oxley Act (SOX),
- US's Health Insurance Portability and Accountability Act (HIPAA),
- Payment Card Industry Data Security Standard (PCI-DSS).
This security audit program contains over 400 unique tasks. These are divided into 11 areas of audit focus, which are then divided into 38 separate task groupings.
The 11 areas of audit focus and objectives are:
-
Corporate Security Management
-
Systems Development and Maintenance
-
Information Access Control Management
-
Compliance Management
-
Human Resource Security Management
-
Information Security Incident Management
-
Communications and Operations Management
-
Organisational Asset Management
-
Physical and Environmental Security Management
-
Security Policy Management
-
Disaster Recovery Plan and Business Continuity
This tool is made up of Microsoft (2003 and 2007 format) Excel workbooks and an indexed PDF document that contain the following:
-
Read Me - General instructions on the use of the Excel worksheets
-
Security Audit Program Summary - Lists the 11 areas of audit focus and the 38 task groupings that are included within the audit. The point summary on this worksheet is calculated automatically by Excel.
-
Security Audit Program Detail - Lists over 400 detailed tasks that need to be completed in the audit and the relative point value of each task. The only thing that the user needs to do is check the yes or no on each item, and re-assign a relative point value for each task.
-
Security Audit Program Graphic - Lists the 11 areas of audit focus and a bar graph which shows the weights that are assigned to each area. The point summary on this worksheet is calculated automatically by Excel. The graph is automatically updated.
-
Sample Security Audit Program - This is copy of the Security Audit Program with data entered into the individual tasks.
-
Sample Security Audit Program Summary - This is a copy of the Security Audit Program Summary with the links changed to point to the Sample Security Audit Program.
-
Sample Security Audit Program Graphic - This is a copy of the Security Audit Program Graphic with links changed to point to the Sample Security Audit Program plus a chart has been added to show the positive and negative points of the audit. (See chart below)

This is a summary graphic that was produced from the Security Audit Program. In the sample above it is easy to see those areas where improvement is need.
Publisher: Janco Associates
Format: Single-User Electronic Download (Zipped Microsoft Excel 2003 & 2007 & .PDF 0.750MB)
Availability: Immediate Download
Order this vital tool today to aid you with your security audits.
To write review for this product Click here
RELATED PRODUCTS