-

ISACA Launches New Audit Program for Security Incident Management

Auditors can access clear control objectives, controls and testing steps for each step of the assurance process

SCHAUMBURG, Ill.--(BUSINESS WIRE)--Security incidents are only growing in number—according to ISACA’s 2019 State of Cybersecurity survey report, part 2, 46 percent of respondents believe that their enterprises are experiencing an increase in attacks relative to last year. In light of this, incident management programs are more important than ever, and with ISACA’s newly launched Security Incident Management Audit Program, audit professionals now have the tools to more effectively evaluate incident management programs and achieve greater assurance.

The audit program covers process areas of security incident management programs and clearly outlines process sub-areas—like detection and analysis, forensics, and change management during program implementation as well as control objectives, controls and testing steps in a customizable spreadsheet. The audit program examines assurance across areas such as:

  • Program design and implementation—Exploring processes including risk analysis; awareness and training; detection and analysis; and containment, eradication and recovery
  • Tools and technologies—Covering areas such as software, vulnerability assessments, and configurations of workstations and servers
  • Reporting best practices—Including reports and escalation documents, as well as a formal process for root cause analysis
  • Lessons learned—Factoring in steps such as a protocol for post-incident reflection

“Security incidents not only result in added expenses, but can damage a company’s reputation—so enterprises need to ensure that security incident management programs are effective,” said Beverly Thomas, CISA, expert reviewer for the audit program, and Senior Manager, Internal Audit, UMWA Health & Retirement Funds. “Having an organized audit program to assess these programs is an important part of driving their success.”

The Security Incident Management Audit Program is US $25 for ISACA members and US $49 for non-members. To access, visit www.isaca.org/bookstore/audit-control-and-security-essentials/wapim2. To explore additional audit programs and other resources, visit www.isaca.org/resources.

About ISACA

For more than 50 years, ISACA® (www.isaca.org) has advanced the best talent, expertise and learning in technology. ISACA equips individuals with knowledge, credentials, education and community to progress their careers and transform their organizations, and enables enterprises to train and build quality teams. ISACA is a global professional association and learning organization that leverages the expertise of its 145,000 members.

Contacts

Emily Van Camp, evcamp@isaca.org, +1.847.385.7223
Kristen Kessinger, communications@isaca.org, +1.847.660.5512

ISACA


Release Versions

Contacts

Emily Van Camp, evcamp@isaca.org, +1.847.385.7223
Kristen Kessinger, communications@isaca.org, +1.847.660.5512

Social Media Profiles
More News From ISACA

Only 8 Percent of Organizations Conduct Regular AI-Specific Response Exercises, ISACA Research Finds

SCHAUMBURG, Ill.--(BUSINESS WIRE)--With rogue AI model behavior in the news recently, new research from ISACA finds concerning news about AI security. While AI is being heavily leveraged within cybersecurity teams, only eight percent of organizations indicate they conduct AI-specific response exercises regularly, according to ISACA’s 2026 State of Cybersecurity report, which surveyed more than 1,800 cybersecurity professionals across the globe. AI incident response planning lags, even as AI tra...

Cyber Teams Stretched Too Thin as Attacks Intensify and Budgets Shrink, ISACA Research Finds

LONDON--(BUSINESS WIRE)--Cyberattacks are rising, but the teams defending against them are not growing to keep pace. Four in ten (38%) European IT and cybersecurity professionals say their organisation faced more attacks this year than last, yet more than half remain understaffed (56%) and underfunded (55%), according to new research from ISACA. According to ISACA's 2026 State of Cyber report, attacks are expected to rise further, with half of cyber professionals (54%) saying it’s likely their...

ISACA Foundation Scholarship Program Expands Access to Tech and Cybersecurity Education

SCHAUMBURG, Ill.--(BUSINESS WIRE)--New ISACA Foundation scholarship applications are open now for undergraduate and graduate students seeking opportunities in IT and cybersecurity...
Back to Newsroom