-

ISACA Launches New Audit Program for Security Incident Management

Auditors can access clear control objectives, controls and testing steps for each step of the assurance process

SCHAUMBURG, Ill.--(BUSINESS WIRE)--Security incidents are only growing in number—according to ISACA’s 2019 State of Cybersecurity survey report, part 2, 46 percent of respondents believe that their enterprises are experiencing an increase in attacks relative to last year. In light of this, incident management programs are more important than ever, and with ISACA’s newly launched Security Incident Management Audit Program, audit professionals now have the tools to more effectively evaluate incident management programs and achieve greater assurance.

The audit program covers process areas of security incident management programs and clearly outlines process sub-areas—like detection and analysis, forensics, and change management during program implementation as well as control objectives, controls and testing steps in a customizable spreadsheet. The audit program examines assurance across areas such as:

  • Program design and implementation—Exploring processes including risk analysis; awareness and training; detection and analysis; and containment, eradication and recovery
  • Tools and technologies—Covering areas such as software, vulnerability assessments, and configurations of workstations and servers
  • Reporting best practices—Including reports and escalation documents, as well as a formal process for root cause analysis
  • Lessons learned—Factoring in steps such as a protocol for post-incident reflection

“Security incidents not only result in added expenses, but can damage a company’s reputation—so enterprises need to ensure that security incident management programs are effective,” said Beverly Thomas, CISA, expert reviewer for the audit program, and Senior Manager, Internal Audit, UMWA Health & Retirement Funds. “Having an organized audit program to assess these programs is an important part of driving their success.”

The Security Incident Management Audit Program is US $25 for ISACA members and US $49 for non-members. To access, visit www.isaca.org/bookstore/audit-control-and-security-essentials/wapim2. To explore additional audit programs and other resources, visit www.isaca.org/resources.

About ISACA

For more than 50 years, ISACA® (www.isaca.org) has advanced the best talent, expertise and learning in technology. ISACA equips individuals with knowledge, credentials, education and community to progress their careers and transform their organizations, and enables enterprises to train and build quality teams. ISACA is a global professional association and learning organization that leverages the expertise of its 145,000 members.

Contacts

Emily Van Camp, evcamp@isaca.org, +1.847.385.7223
Kristen Kessinger, communications@isaca.org, +1.847.660.5512

ISACA


Release Versions

Contacts

Emily Van Camp, evcamp@isaca.org, +1.847.385.7223
Kristen Kessinger, communications@isaca.org, +1.847.660.5512

Social Media Profiles
More News From ISACA

New Security Debt Index Model from ISACA Helps Organizations Track Overall Debt Posture

SCHAUMBURG, Ill.--(BUSINESS WIRE)--As businesses accelerate their adoption of cloud technologies and artificial intelligence (AI), security debt— the accumulated risk created by outdated systems, deferred remediation, unpatched vulnerabilities, and under-resourced programs—has become one of the largest threats to enterprise resilience. Unpatched systems, weak identity and access management, siloed monitoring and alerting, and gaps in governance and oversight are just some examples of security d...

ISACA Digital Trust Workforce Development Program to Prepare More than 130 Learners for Tech Jobs in 2026

SCHAUMBURG, Ill.--(BUSINESS WIRE)--ISACA and the ISACA Foundation are expanding the ISACA Digital Trust Workforce Development Program in select cities across the United States. The expansion was made possible thanks to a grant from the Caterpillar Foundation to the ISACA Foundation. The ISACA Digital Trust Workforce Development Program helps individuals build practical, job-ready skills and earn ISACA certificates that support entry into the IT workforce. The program’s courses, which are suppor...

AI Use Accelerates, While Governance and ROI Lag, Says New ISACA Research

SCHAUMBURG, Ill.--(BUSINESS WIRE)--While 90 percent believe employees are using artificial intelligence in their organization, only 22 percent say AI return on investment (ROI) has met or exceeded their expectations, according to ISACA’s new 2026 AI Pulse Poll. With responses from more than 3,400 digital trust professionals across IT audit, governance, cybersecurity, privacy and emerging technology roles, ISACA’s poll finds that AI has become embedded in day-to-day work; however, governance and...
Back to Newsroom