In Depth

Here Come the Auditors: Judgment Calls

Regulations such as Sarbanes-Oxley are sending auditors to the pencil sharpener. CSOs must learn to cooperate and share expertise, without getting too close to these empowered examiners.

By Malcolm Wheatley

Page 6

"Audit and infosec don't see thingsor thinkin the same way," Ikbal says. "A fundamental difference is responsibility. Audit's role begins and ends with finding gaps and following those up until either they are closed, or management accepts the risks. Infosec does exactly the same thing, but they are the ones who close the gaps and get audited on the follow-up as well."

At the end of the day, Koletar says he is an enthusiastic advocate of the principle of audit and security working closely together. But he doesn't want to see CSOs overestimate the audit function's strength.

It seems even the auditors want to retain some tension in the relationship.

Other stories by Malcolm Wheatley

$firstKeyword

RESOURCE CENTER
Loading...
VIRTUAL CONFERENCE
Security Directions: A Virtual Conference

Security Directions Available On Demand Sept. 30 - Dec. 30

Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.

» Register Now

WEBCAST
Protecting PII: How to Work with IT to Manage Risk

Compuware Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.

» View this Webcast

Featured Sponsors