Is a comprehensive IT audit permanently on your checklist when stepping into a new CIO position? If not, what on your checklist is etched in stone?
Sort by:
CIO in Banking3 months ago
Audit should be on top of your priority list, actually it is one of the main sources for blind spots of your predecessors, same as the regulator fines, announcements, new regulations and deadlines.
Incident reports, whether related to availability or security, would reveal a lot.
Impartial third-party data is essential, but the fact that the organization has unique processes that could at first glance look incorrect, is important.
An audit finding due to lack of layered controls protecting medical information means something different in an insurance company and an emergency medical care provider. A patient’s health could depend upon how quickly the medical caregiver can access the patient’s medical information while an insurance provider has time for more robust, overlapping protections.
Information without context is noise.