Chris McClean serves Security & Risk Professionals. See the full Analyst bio.
Visit Forrester.com to learn how we make Security & Risk Professionals successful every day.
How Should Auditors Deal With Such Oddities?
Posted by Chris McClean on September 9, 2009
- 199 Recommendations
- 0 comments

Two weeks ago, I commented on the changing role of the risk management professional, and thought it would be worthwhile to spend a few moments discussing the auditor as well. In a contest of which job is likely to see more change in the next two years, I would expect a photo finish.
Over on the Institute of Internal Auditors (IIA) site, Norman Marks started an interesting discussion about continued fallout from the Heartland data breach. In a Q&A interview with CSO Online, an understandably defensive CEO Robert Carr states that the company’s Qualified Security Assessors (PCI auditors) were worthless and gave them false reports for the previous six years suggesting that their security systems were just fine. I don’t think we need to dwell on the concept that compliance with security standards does not equal total security, however this does bring up a more interesting debate about the role of the auditors.
As expectations for greater corporate accountability and disclosure continue to mount (some would say more slowly than expected) audit reports are going to be set under the most finely tuned of microscopes to be examined for accuracy and thoroughness. Two of the most important questions auditors will have to answer will be:
- What is the scope of the audit? This must include what is evaluated and what is not as well as what justification exists for including or excluding specific elements.
- What are the auditors assessing specifically? This must spell out very clearly the purpose for the audit (e.g. We are evaluating whether or not these systems are compliance with PCI, no other opinions should be inferred from this report).
If this information is not clear, both sides are left exposed. Would an auditor be demonstrating additional value and good faith by calling out other possible issues outside of their official report? Yes. However, it would be unfair to expect them to volunteer information that is beyond their defined scope... there is more than enough pressure as it is to get that right.
[Posted by Chris McClean]
search forrester's blogs
Secure the digital business future.
Attend Forrester’s Forum for Security & Risk Professionals EMEA, June 10-11, London UK
Analyst Blogs
- Andras Cser (31)
- Andrew Rose (17)
- Chris McClean (54)
- Christopher Sherman (1)
- Edward Ferrara (20)
- Eve Maler (19)
- Heidi Shey (9)
- John Kindervag (28)
- Khalid Kark (13)
- Laura Koetzle (2)
- Nick Hayes (5)
- Rick Holland (20)
- Stephanie Balaouras (50)
Top Categories
- GRC (21)
- Enterprise Risk Management (10)
- Governance Risk and Compliance (2)
- IT Risk Management (2)
- IT security (2)
- acquisitions (1)
- BC/DR (1)
- BT Resiliency (1)
- Business continuity (1)
- business technology resiliency (1)
- See all
Archives
- March 2013 (1)
- February 2013 (1)
- November 2012 (1)
- May 2012 (2)
- March 2012 (1)
- November 2011 (1)
- October 2011 (1)
- September 2011 (1)
- May 2011 (1)
- February 2011 (2)
- January 2011 (1)
- December 2010 (1)
- November 2010 (1)
- See all