When it comes to a company’s information security, it is better to be safe than sorry than to suffer from information leaks, cyberattacks, or data theft. Every information security incident usually results in financial losses and reputational risks for the business, causing even loyal customers to lose trust in the company.
IT infrastructure and information security processes can be checked using internal and external information security audits. In this article, we work with ITG Security specialists to understand why information security audits are necessary and the similarities and differences between external and internal audits.
Why do you need an information security audit?
Businesses conduct information security audits to improve their overall information security, ensure the security of their IT infrastructure, assess the maturity of their information security processes, and obtain a detailed report with recommendations for improvement.
Internal audits are more focused on self-monitoring, where company specialists independently identify weaknesses in their information security and eliminate them. For example, they configure access rights to applications and IT infrastructure components according to the principle of least privilege. An external audit helps to obtain an objective assessment of the security status of the company’s IT infrastructure and information security processes from a third-party organization. It is most often conducted when an information security incident has occurred or when it is necessary to verify compliance with the requirements of Russian regulatory and legal acts.
How to understand that your business needs an audit
You don’t need to wait for an information security incident or management instructions to conduct an internal audit. It is a regular check where data and process handling must be clearly regulated in internal documents and the company’s charter.
There are two types of internal audits:
- an information security department employee checks how company data is protected and how information security processes are organized in the IT department;
- the head of the information security department checks the processes and work of employees in their department.
The data that needs to be protected depends on the company’s field of activity. This could be state secrets, trade secrets, or customers’ personal data. An external audit can be initiated by the business itself when an information security incident has occurred and similar situations need to be prevented in the future. Or when the regulator has information security requirements that the company must comply with. For example, for banks, financial, and government organizations, conducting an external audit is an obligation stipulated in the regulatory acts of the Russian Federation and GOST.
When is it necessary to conduct an additional external audit:
- new regulatory requirements appear;
- the company undergoes reorganization;
- there are changes in key IT positions;
- new strategic business plans appear;
- management evaluates the company’s assets;
- Information security management processes are transformed;
- top managers are evaluating the qualifications of IT/information security department employees.
Who conducts the information security audit
The company conducts an internal information security audit using its own information security and IT departments. Unlike an internal audit, an external information security audit is an independent check that the business orders from a third-party licensed company. For example, ITG Security has the following licenses to conduct auditing activities:
- FSTEC (Federal Service for Technical and Export Control) for TZKI (Technical Protection of Confidential Information);
- FSB license for cryptography;
- ISO 27001 certificate (Information Security Management Standard).
How to prepare for an audit
Before conducting an internal audit, the company’s information security department employees must prepare an internal document that outlines the entire audit process step by step: a list of information security systems and processes, the content of final reports, and a schedule for subsequent audits.
External audits are conducted by third-party organizations, so the preparation is slightly different. For example, ITGLOBAL.COM Security specialists must sign an NDA with the client before starting work, specify the business requirements for the audit in the contract, including information about what constitutes protected information (personal data, state secrets, etc.) and where the boundaries of the information security audit lie.
The auditors then study the company’s business processes, the composition and settings of the IT infrastructure and application services, and check the current settings of the information security systems (ISS). They conclude which components of the IT infrastructure and processes require special attention.
What is checked during the audit
An internal audit can be used to check how information security processes are organized within a company. For example, to find unblocked accounts where a former employee can still access the company’s IT infrastructure under their own name, steal confidential information, and sell it to competitors.
During an internal audit, specialists:
- establish employee access rights to information;
- check the status of data protection measures;
- check employees’ awareness of internal information security rules.
An external audit is more focused on assessing the security of the IT infrastructure and its resilience to threats, data leakage risks, and data protection issues. This applies to both the network level and the level of individual components of the information system. During an external audit, specialists check:
- the state of the IT infrastructure, equipment, and corporate software;
- the state of information security systems and processes, the level of data protection, and access settings;
- the qualifications of the company’s IT specialists.
How often to conduct an audit
The frequency of internal audits is determined by the company itself: once a month, once every two months, or once every six months. ITG Security specialists recommend conducting internal audits four times a year. External audits should be conducted at least once or twice a year, but it all depends on the business objectives and the impact of information security on the company’s activities.
How do the results of internal and external audits differ?
Based on the results of internal and external audits, specialists compile detailed reports with information on the security of the IT infrastructure, the state of information security processes, and their compliance (or non-compliance) with international best practices. The only difference between the reports is that the internal audit report is prepared by the company’s information security department, while the external audit report is prepared by certified specialists from a third-party organization. After receiving a detailed external audit report, the company can eliminate any non-compliance issues either independently or with the help of ITG Security specialists.
Summary: the main differences between internal and external audits
- Purpose. The main purpose of audits is to improve the overall information security of the company. However, internal audits are more focused on ensuring self-control, while external audits are aimed at building information security processes in accordance with international best practices and regulatory requirements.
- Circumstances. An internal audit is a regular check that does not require a specific reason. An external audit is conducted by the company on its own initiative (for example, when an information security incident has occurred) or at the request of regulators. This applies to banks, financial institutions, and government organizations.
- Auditor. An internal audit is conducted by the company itself using its own information security department, while an external audit is conducted by an independent third-party organization that has all the necessary certificates: FSTEC of Russia for technical means of information protection, FSB, ISO 27001 certificate.
- Preparation. Before an internal audit, the information security department specialists prepare an internal document describing the entire audit process. Before an external audit, the company enters into an agreement with a third-party organization, which first immerses itself in the company’s business processes and studies its information security processes.
- Subject of the audit. During an internal audit, the company’s specialists check employees’ access rights to confidential information, accounts, etc. An external audit is more focused on checking the security of the IT infrastructure as a whole and information security processes.
- Frequency. ITG Security experts recommend conducting internal audits four times a year and external audits at least once or twice a year. However, it all depends on the business objectives and the impact of information security on the company’s activities.
- Reporting. Based on the results of the audits, specialists compile a detailed report on the state of information security processes and provide recommendations on what needs to be corrected to bring them into line with best international practices. The only difference is that the external audit report is written by independent experts, so the business receives more complete and objective information.