-

ISACA Introduces New Audit Programs on Identity and Access Management and Ransomware Readiness

SCHAUMBURG, Ill.--(BUSINESS WIRE)--The rapid increase of remote access due to remote and hybrid work arrangements requires increased organizational risk management. At the same time, organizations must be prepared for ransomware attacks as threat actors focus on generating revenue streams by extorting users and organizations of all sizes. These drivers have led to ISACA creating two new audit programs on identity and access management (IAM) and ransomware readiness to better prepare audit professionals for the current landscape.

ISACA’s Identity and Access Management Audit Program provides specific testing and evaluation criteria to assist auditors in assessing the adequacy of safeguards in place to mitigate IAM risk.

IAM processes need to be implemented for all enterprises, but the level of automation within the processes will vary on organizational size and maturity. The audit program outlines common risk related to IAM that auditors should keep in mind, including:

  • Excessive access to systems and data
  • Weak authentication
  • Disclosure of user credentials

ISACA’s Ransomware Readiness Audit Program highlights potential business impacts of poor ransomware readiness, including:

  • Loss of staff productivity
  • Missing performance targets
  • Loss of consumer and stakeholder confidence in the safety of their data
  • Increased rate of attacks in the future

When developing an enterprise ransomware policy and planning for appropriate investments in attack countermeasures, the enterprise’s risk tolerance and its ability to withstand a business disruption must be considered. The audit program provides foundational information, practical guidance and approaches to preparing for and recovering from a ransomware-related incident addressing the following key areas:

  • Governance
  • Information protection processes and procedures
  • Technical safeguards
  • Human safeguards

Both audit programs are free for ISACA members and US$49 for nonmembers. The Identity and Access Management Audit Program can be accessed at https://store.isaca.org/s/store#/store/browse/detail/a2S4w000005Grc7EAC and the Ransomware Readiness Audit Program can be accessed at https://store.isaca.org/s/store#/store/browse/detail/a2S4w000005uz6vEAA. Additional audit programs and tools from ISACA can be found at https://www.isaca.org/resources/insights-and-expertise/audit-programs-and-tools.

About ISACA

ISACA® (www.isaca.org) is a global community advancing individuals and organizations in their pursuit of digital trust. For more than 50 years, ISACA has equipped individuals and enterprises with the knowledge, credentials, education, training and community to progress their careers, transform their organizations, and build a more trusted and ethical digital world. ISACA is a global professional association and learning organization that leverages the expertise of its more than 165,000 members who work in digital trust fields such as information security, governance, assurance, risk, privacy and quality. It has a presence in 188 countries, including 225 chapters worldwide. Through its foundation One In Tech, ISACA supports IT education and career pathways for underresourced and underrepresented populations.

Twitter: www.twitter.com/ISACANews
LinkedIn: www.linkedin.com/company/isaca
Facebook: www.facebook.com/ISACAGlobal
Instagram: www.instagram.com/isacanews

Contacts

Bridget Drufke, bdrufke@isaca.org, +1.847.660.5554
Emily Ayala, communications@isaca.org, +1.847.385.7223

ISACA


Release Versions

Contacts

Bridget Drufke, bdrufke@isaca.org, +1.847.660.5554
Emily Ayala, communications@isaca.org, +1.847.385.7223

Social Media Profiles
More News From ISACA

AI Governance, Cyber Resilience and Digital Trust to Take Centre Stage at ISACA Europe Conference 2026 in Munich

MUNICH--(BUSINESS WIRE)--As artificial intelligence transforms organisations faster than governance frameworks can keep pace, professionals across Europe are under growing pressure to ensure AI is not only adopted, but governed, secured and managed responsibly. Against that backdrop, ISACA Europe Conference 2026 will bring more than 50 international speakers to Munich from 7–9 October to examine how organisations can strengthen oversight, manage risk and build resilience in an increasingly comp...

ISACA Introduces 2026-2027 Board of Directors

SCHAUMBURG, Ill.--(BUSINESS WIRE)--ISACA has installed its 2026-2027 Board of Directors during the association’s Annual General Meeting held today in Chicago, Illinois, USA, and virtually. New Board Chair Massimo Migliuolo and returning Board Vice Chair Jamie Norton will lead the global professional association that champions the workforce in fields including IT audit, governance, risk, privacy and cybersecurity.Migliuolo, a past ISACA board director, is a globally experienced technology executi...

New Security Debt Index Model from ISACA Helps Organizations Track Overall Debt Posture

SCHAUMBURG, Ill.--(BUSINESS WIRE)--As businesses accelerate their adoption of cloud technologies and artificial intelligence (AI), security debt— the accumulated risk created by outdated systems, deferred remediation, unpatched vulnerabilities, and under-resourced programs—has become one of the largest threats to enterprise resilience. Unpatched systems, weak identity and access management, siloed monitoring and alerting, and gaps in governance and oversight are just some examples of security d...
Back to Newsroom