IT Security Auditing
Internal & External Security Auditing
An internal security audit focuses on company employees to determine if they are following IT security best practises and procedures. An external security audit examines the company’s IT security service providers to ensure that the company is as well protected as they think that they are.
“Who is guarding the guards?”
Internal Security Auditing
The goal of this audit is to highlight compliance practices, document gaps, shadow IT, poor data handling and low training uptake. Continuous improvement is then managed through follow-up audits, feedback loops and metrics to benchmark progress over time.
Planning, Policy and Technical Controls
- Objectives & scope: Define drivers (compliance, contracts, internal risks) and target high-risk areas (privileged access, sensitive data, remote work).
- Policy review: Check Acceptable Use, data protection, and remote working policies are current, standard-aligned, and acknowledged.
- Technical controls: Verify strong authentication (passwords, MFA), least privilege, log monitoring, patching, antivirus, encryption, and secure data transfer.
Behaviour and Awareness
- Work practices: Assess through observation, interviews, and walkthroughs. Focus on data handling, password use, screen-locking, access control, and remote work (VPN, device security, safe networks). Test with phishing or social engineering exercises.
- Training & awareness: Review completion of mandatory modules, frequency of refreshers, and knowledge retention (quizzes, scenarios). Evaluate content quality, role relevance, and adaptability to emerging threats.
Compliance Metrics and Key Indicators
- % of employees using MFA and strong password policies.
- % of unpatched endpoints by employee ownership.
- Phishing susceptibility rate (click-throughs, credential submissions).
- % of employees completing mandatory training.
- Number of policy violations or near misses reported.
External Security Auditing
The goal of this audit is to identify key IT security services within an organisation and then verify that these security services are aligned with organisational policies, regulatory requirements, and security frameworks.
Access, Network And System Security
- Perimeter and network protection: Review firewalls, IDS/IPS, and SIEM coverage; check configuration, rulebases, and patch/vulnerability management.
- Access controls: Verify authentication strength (MFA, SSO), role-based access rights, and adherence to least privilege.
- Monitoring: Assess logging of access and network events, anomaly detection, and integration with incident response processes.
Data, Endpoint And Application Security
- Endpoint protection: Confirm deployment and update status of antivirus/EDR, secure configuration of devices, and mobile device management.
- Application security: Review patching, vulnerability management, and secure development practices.
Data protection: Assess backup frequency, encryption, recovery testing, DLP measures, and cloud security controls for SaaS/IaaS.
Incident Response, Resilience, and Continuous Improvement
- Incident handling: Review detection, escalation, containment, and recovery processes, ensuring integration with monitoring and threat intelligence.
- Business continuity: Assess disaster recovery plans, backup restoration tests, and alignment with resilience standards.
- Performance metrics: Track mean time to detect (MTTD), mean time to respond (MTTR), and incident resolution rates.
- Continuous improvement: Document lessons learned, update playbooks, and recommend optimisation of services or additional controls.