Security Park, the leading online news site for security professionals
Home | About us | Contact us | Submit an article | Advertise | Sales leads | Newsletter | RSS Newsfeed | SEARCH




Develop an ISO 27001-compliant Information Security Management System
This useful guide clarifies the steps you have to follow to develop an ISO 27001-compliant ISMS. Each step is integral in how secure your information security system is.

Need a
reference book?
Find it on Amazon:
Security books and magazines in association with Amazon.co.uk

SecurityPark Research Library

Help | Advanced Search
What's New?
What's Popular?
Audit Trail: Inside the Mind of an IT Auditor
sponsored by CIO Decisions
Posted:  14 Aug 2005
Published:  01 Aug 2005
Format:  HTML
Length:  1   Page(s)
Type:  Journal Article
Language:  English


ABSTRACT:
To make sure an audit does what it's intended to do -- reduce risk to acceptable levels -- everyone involved must use the same words in the same way. You'd be amazed by how often that's not the case with words as seemingly basic as policy, standards and controls. That confusion results in a lot of head-scratching and wasted effort.

Here's list of some of the most misinterpreted words, along with explanations of what IT auditors mean when we say them.

  • Policy
  • Standards
  • Controls


Author

Matt Zerega
IT auditor ,  CIO Decisions
Matt Zerega is a West Coast IT auditor who has worked in energy, electronics and other fields. Write to him at AuditTrail@ciodecisions.com.



BROWSE RELATED RESOURCES
IT Auditing

View All Resources sponsored by CIO Decisions

Library Home | Advertise with Us | Product Library
A Service of Bitpipe