Published: 28 February 2024
Summary
Security audit findings can benefit an organization by highlighting weaknesses which may otherwise remain unknown. Cybersecurity leaders such as chief information security officers can use this research to make the most of the security audit findings after an audit is complete.
Included in Full Research
Overview
Key Findings
Cybersecurity professionals and senior leadership often interpret audit findings as failures or conversely, get a false sense of immunity when there are no notable findings in the report.
Prior to an audit, cybersecurity leaders may feel an urgency to find and resolve issues before they are reported as findings. After it, however, this urgency can diminish, potentially leading to a slowdown in communication and addressing the findings.
After going through an audit, an organization often focuses its attention on the reported audit findings and fixing specific controls and gaps. As a result, it overlooks continuous vigilance and fails to draw
Clients can log in to view the entire
document.