Skip to content
BOL Conferences
Thread Options
#2065671 - 02/23/16 11:17 PM IT Audit
INOH Offline
Gold Star
Joined: Jul 2012
Posts: 345
Northeast
Is the vulnerability scan part of the IT audit or is this part of the penetration test?

Thanks,
_________________________
Just trying to swim in the compliance world.

Return to Top
Audit
#2065930 - 02/24/16 11:56 PM Re: IT Audit INOH
RR Jen Offline
Power Poster
RR Jen
Joined: May 2003
Posts: 3,760
Running and riding everywhere ...
I've historically included both as well as the internal controls piece.
_________________________
I don't need any more negativity in my life...be positive and helpful people or I will kick you in the shins!!!

Return to Top
#2065983 - 02/25/16 02:55 PM Re: IT Audit RR Jen
Cornfed Turtle Offline
Diamond Poster
Joined: Mar 2006
Posts: 1,323
"...Somewhere in Middle Americ...
We schedule the scans, the pen tests and the IT audit as three separate engagements. The scans are the most frequent and then the pen tests. When we schedule the IT audit (the internal controls piece as Jen says,) we discuss how long it's been since the scans or pens. May or may not repeat during the audit, but it's usually a separate engagement.

Return to Top
#2066002 - 02/25/16 03:29 PM Re: IT Audit INOH
INOH Offline
Gold Star
Joined: Jul 2012
Posts: 345
Northeast
Thank you!
_________________________
Just trying to swim in the compliance world.

Return to Top

Moderator:  Andy_Z