1
00:00:00,120 --> 00:00:00,953
In this lesson

2
00:00:00,953 --> 00:00:03,362
we're going to discuss internal audits and assessments.

3
00:00:03,362 --> 00:00:07,080
Maintaining a robust and secure environment is challenging

4
00:00:07,080 --> 00:00:09,030
and it involves not only implementing

5
00:00:09,030 --> 00:00:10,290
strong security measures,

6
00:00:10,290 --> 00:00:13,200
but also regularly evaluating the effectiveness

7
00:00:13,200 --> 00:00:14,580
of those security measures.

8
00:00:14,580 --> 00:00:17,340
Two key processes that help organizations achieve this

9
00:00:17,340 --> 00:00:19,650
are internal audits and assessments.

10
00:00:19,650 --> 00:00:22,770
Internal audits and assessments are proactive measures

11
00:00:22,770 --> 00:00:25,500
that organizations undertake to ensure the robustness

12
00:00:25,500 --> 00:00:28,680
of their security posture while they serve distinct purposes

13
00:00:28,680 --> 00:00:30,690
and focus on different aspects

14
00:00:30,690 --> 00:00:32,970
of an organization's security infrastructure.

15
00:00:32,970 --> 00:00:34,880
First, we have internal audits.

16
00:00:34,880 --> 00:00:37,680
Internal audits are systematic evaluations

17
00:00:37,680 --> 00:00:40,350
conducted by an organization's own audit team

18
00:00:40,350 --> 00:00:42,990
to assess the effectiveness of internal controls,

19
00:00:42,990 --> 00:00:44,460
compliance with regulations,

20
00:00:44,460 --> 00:00:47,912
and the integrity of information systems and processes.

21
00:00:47,912 --> 00:00:50,820
Internal audits often focus on areas

22
00:00:50,820 --> 00:00:53,340
such as data protection, network security,

23
00:00:53,340 --> 00:00:56,554
access controls, and incident response procedures.

24
00:00:56,554 --> 00:01:00,450
For example, an internal audit might involve a review

25
00:01:00,450 --> 00:01:02,730
of the organization's password policies.

26
00:01:02,730 --> 00:01:04,156
The audit team would check

27
00:01:04,156 --> 00:01:06,900
whether the policies align with best practices

28
00:01:06,900 --> 00:01:08,730
such as requiring complex passwords

29
00:01:08,730 --> 00:01:10,220
and regular password changes

30
00:01:10,220 --> 00:01:12,960
and whether these policies are being followed correctly

31
00:01:12,960 --> 00:01:15,060
by all employees.

32
00:01:15,060 --> 00:01:17,400
Another example would be an organization's

33
00:01:17,400 --> 00:01:20,070
internal audit team deciding to conduct an audit

34
00:01:20,070 --> 00:01:22,350
of the company's user access controls.

35
00:01:22,350 --> 00:01:23,790
This audit is designed to ensure

36
00:01:23,790 --> 00:01:25,950
that only authorized individuals have access

37
00:01:25,950 --> 00:01:27,720
to sensitive data and systems.

38
00:01:27,720 --> 00:01:29,310
The audit team begins by reviewing

39
00:01:29,310 --> 00:01:31,890
the company's access control policies and procedures.

40
00:01:31,890 --> 00:01:33,900
They check if these policies are in line again

41
00:01:33,900 --> 00:01:36,300
with the best practices and regulatory requirements

42
00:01:36,300 --> 00:01:38,370
such as the principle of least privilege

43
00:01:38,370 --> 00:01:40,259
and the segregation of duties.

44
00:01:40,259 --> 00:01:43,620
Next, the team will perform a detailed examination

45
00:01:43,620 --> 00:01:46,290
of the access rights granted to different users

46
00:01:46,290 --> 00:01:47,490
within the organization.

47
00:01:47,490 --> 00:01:50,100
They verify whether employees have access rights

48
00:01:50,100 --> 00:01:52,293
that align with their job responsibilities

49
00:01:52,293 --> 00:01:55,144
and whether there are any instances of excessive

50
00:01:55,144 --> 00:01:57,900
or unnecessary access.

51
00:01:57,900 --> 00:02:00,616
The audit team will then check the processes for granting,

52
00:02:00,616 --> 00:02:03,118
modifying and revoking access rights

53
00:02:03,118 --> 00:02:06,148
to ensure that there are proper approval processes in place

54
00:02:06,148 --> 00:02:09,180
that access rights are promptly revoked

55
00:02:09,180 --> 00:02:11,970
when an employee leaves the company or changes roles.

56
00:02:11,970 --> 00:02:14,430
Finally, the audit team test the effectiveness

57
00:02:14,430 --> 00:02:15,870
of the access controls by attempting

58
00:02:15,870 --> 00:02:18,840
to access certain systems or data using an account

59
00:02:18,840 --> 00:02:20,220
with limited permissions.

60
00:02:20,220 --> 00:02:21,990
If they're able to access resources

61
00:02:21,990 --> 00:02:24,405
beyond the account's designated permissions

62
00:02:24,405 --> 00:02:27,600
that will indicate a weakness in the access controls.

63
00:02:27,600 --> 00:02:30,300
The findings from this audit would then be documented

64
00:02:30,300 --> 00:02:31,980
and used to recommend improvements

65
00:02:31,980 --> 00:02:35,160
to the company's access control policies procedures.

66
00:02:35,160 --> 00:02:37,260
Now, when it comes to internal audits,

67
00:02:37,260 --> 00:02:39,960
there are a few concepts that you should be familiar with

68
00:02:39,960 --> 00:02:41,730
such as compliance requirements

69
00:02:41,730 --> 00:02:43,868
and the creation of an audit committee.

70
00:02:43,868 --> 00:02:47,117
Now, compliance refers to the process of ensuring

71
00:02:47,117 --> 00:02:49,410
that an organization's information systems

72
00:02:49,410 --> 00:02:53,220
and security practices adhere to established standards,

73
00:02:53,220 --> 00:02:54,814
regulations, and laws.

74
00:02:54,814 --> 00:02:57,833
Compliance is crucial for protecting sensitive data,

75
00:02:57,833 --> 00:02:59,610
avoiding legal penalties,

76
00:02:59,610 --> 00:03:02,189
and maintaining trust with customers and stakeholders.

77
00:03:02,189 --> 00:03:05,070
Compliance can involve a variety of activities

78
00:03:05,070 --> 00:03:07,241
including implementing specific security controls,

79
00:03:07,241 --> 00:03:09,840
maintaining certain policies and procedures,

80
00:03:09,840 --> 00:03:11,910
and regularly auditing and assessing

81
00:03:11,910 --> 00:03:14,130
the organization's security posture.

82
00:03:14,130 --> 00:03:16,020
This is why compliance is important

83
00:03:16,020 --> 00:03:17,940
in terms of internal audit.

84
00:03:17,940 --> 00:03:20,790
Since those internal audits may be required

85
00:03:20,790 --> 00:03:23,280
by some governing law or regulation.

86
00:03:23,280 --> 00:03:26,220
And to ensure compliance with those laws or regulations,

87
00:03:26,220 --> 00:03:28,860
you need to conduct internal audits every quarter

88
00:03:28,860 --> 00:03:30,750
or every year depending on

89
00:03:30,750 --> 00:03:33,570
your industry compliance requirements.

90
00:03:33,570 --> 00:03:35,539
Next, we have audit committees.

91
00:03:35,539 --> 00:03:38,220
An audit committee is a group of individuals

92
00:03:38,220 --> 00:03:40,920
typically members of the company's board of directors

93
00:03:40,920 --> 00:03:43,050
who oversees the organization's audit

94
00:03:43,050 --> 00:03:44,700
and compliance activities.

95
00:03:44,700 --> 00:03:47,700
The audit committee's responsibilities often include

96
00:03:47,700 --> 00:03:50,307
reviewing the organization's financial reporting processes

97
00:03:50,307 --> 00:03:51,806
and internal controls,

98
00:03:51,806 --> 00:03:55,346
overseeing the performance of internal and external audits,

99
00:03:55,346 --> 00:03:57,840
ensuring the organization is in compliance

100
00:03:57,840 --> 00:04:00,000
with legal and regulatory requirements,

101
00:04:00,000 --> 00:04:03,270
and lastly, reviewing and addressing any issues

102
00:04:03,270 --> 00:04:04,830
raised by auditors.

103
00:04:04,830 --> 00:04:07,170
The second major category that we need to cover

104
00:04:07,170 --> 00:04:09,056
is internal assessments.

105
00:04:09,056 --> 00:04:12,529
Internal assessments are different from internal audits.

106
00:04:12,529 --> 00:04:14,310
An internal assessment is used

107
00:04:14,310 --> 00:04:17,826
to conduct an in-depth analysis to identify and evaluate

108
00:04:17,826 --> 00:04:20,130
the potential risk and vulnerabilities

109
00:04:20,130 --> 00:04:22,500
in the organization's information system.

110
00:04:22,500 --> 00:04:24,690
These assessments are often performed

111
00:04:24,690 --> 00:04:26,250
before implementing new systems

112
00:04:26,250 --> 00:04:29,520
or before making significant changes to existing ones.

113
00:04:29,520 --> 00:04:32,563
Most internal assessments are conducted as self-assessments.

114
00:04:32,563 --> 00:04:35,443
These self-assessments are internal evaluations

115
00:04:35,443 --> 00:04:37,500
that are conducted by our organization

116
00:04:37,500 --> 00:04:38,880
to assess its compliance

117
00:04:38,880 --> 00:04:41,123
with specific standards or regulations.

118
00:04:41,123 --> 00:04:43,890
These assessments can be a valuable tool

119
00:04:43,890 --> 00:04:47,250
for identifying gaps in an organization's compliance efforts

120
00:04:47,250 --> 00:04:50,610
and for preparing them for formal audits.

121
00:04:50,610 --> 00:04:52,613
For example, an organization might conduct

122
00:04:52,613 --> 00:04:54,930
a vulnerability assessment on its network.

123
00:04:54,930 --> 00:04:57,060
This would involve using automated tools

124
00:04:57,060 --> 00:04:59,070
to scan the network for known vulnerabilities

125
00:04:59,070 --> 00:05:02,190
such as outdated software or misconfigured firewalls.

126
00:05:02,190 --> 00:05:04,620
The result of the assessment would then be used

127
00:05:04,620 --> 00:05:07,109
to prioritize and address these vulnerabilities.

128
00:05:07,109 --> 00:05:09,480
Another example will be if a software company

129
00:05:09,480 --> 00:05:12,055
is planning to launch a new web application.

130
00:05:12,055 --> 00:05:13,350
Before the launch,

131
00:05:13,350 --> 00:05:16,320
the company security team conducts an internal assessment

132
00:05:16,320 --> 00:05:19,770
to identify potential security risk and vulnerability.

133
00:05:19,770 --> 00:05:22,140
In addition to conducting self-assessments

134
00:05:22,140 --> 00:05:24,510
as part of your internal assessments,

135
00:05:24,510 --> 00:05:26,340
if your organization is large enough

136
00:05:26,340 --> 00:05:29,250
you might also have a dedicated internal assessment group

137
00:05:29,250 --> 00:05:31,860
who travels across the enterprise and helps to assess

138
00:05:31,860 --> 00:05:34,964
the organization's massive sprawling enterprise network.

139
00:05:34,964 --> 00:05:37,140
Regardless of whether a self-assessment

140
00:05:37,140 --> 00:05:40,440
or an assisted internal assessment is being conducted,

141
00:05:40,440 --> 00:05:42,930
the assessors will follow the same basic steps

142
00:05:42,930 --> 00:05:44,325
to conduct their assessment.

143
00:05:44,325 --> 00:05:47,040
Let's walk through an example of your organization

144
00:05:47,040 --> 00:05:49,140
wanting to launch a new web application

145
00:05:49,140 --> 00:05:51,180
into their production environment.

146
00:05:51,180 --> 00:05:54,990
First, the assessment begins with a threat modeling exercise

147
00:05:54,990 --> 00:05:57,180
where the team identifies potential threats

148
00:05:57,180 --> 00:05:59,970
to your application such as a SQL injection,

149
00:05:59,970 --> 00:06:03,087
cross-site scripting, and a denial of service attack.

150
00:06:03,087 --> 00:06:06,180
Next, the team conducts a vulnerability assessment

151
00:06:06,180 --> 00:06:08,730
using a combination of automated scanning tools

152
00:06:08,730 --> 00:06:10,770
and manual testing techniques.

153
00:06:10,770 --> 00:06:12,810
They will systematically test the application

154
00:06:12,810 --> 00:06:14,010
for known vulnerabilities

155
00:06:14,010 --> 00:06:16,590
and any potential weaknesses in this code.

156
00:06:16,590 --> 00:06:19,140
Then the team will perform a risk assessment

157
00:06:19,140 --> 00:06:21,270
to evaluate the potential impact

158
00:06:21,270 --> 00:06:23,790
of the identified threats and vulnerability.

159
00:06:23,790 --> 00:06:25,770
The team will also consider factors

160
00:06:25,770 --> 00:06:27,967
such as the likelihood of the threat being exploited,

161
00:06:27,967 --> 00:06:30,180
the potential damage that it could cause,

162
00:06:30,180 --> 00:06:33,060
and the cost of implementing security measures.

163
00:06:33,060 --> 00:06:36,300
Based on the results of their assessment up to this point

164
00:06:36,300 --> 00:06:38,670
the team will recommend mitigation strategies

165
00:06:38,670 --> 00:06:41,351
to address the identified risk and vulnerabilities.

166
00:06:41,351 --> 00:06:43,265
These might include code fixes,

167
00:06:43,265 --> 00:06:46,320
implementation of additional security controls,

168
00:06:46,320 --> 00:06:49,095
or changes to the application's architecture.

169
00:06:49,095 --> 00:06:53,040
This internal assessment is then used to help the company

170
00:06:53,040 --> 00:06:56,100
to proactively address potential security issues

171
00:06:56,100 --> 00:06:59,310
so that they can reduce the risk of security breaches

172
00:06:59,310 --> 00:07:00,840
after the application is launched

173
00:07:00,840 --> 00:07:02,910
into your production environment.

174
00:07:02,910 --> 00:07:06,630
So remember, both internal audits and assessments

175
00:07:06,630 --> 00:07:09,464
are proactive measures to ensure the robustness

176
00:07:09,464 --> 00:07:11,866
of an organization's security posture.

177
00:07:11,866 --> 00:07:14,460
Internal audits focus on evaluating

178
00:07:14,460 --> 00:07:16,440
the effectiveness of internal controls

179
00:07:16,440 --> 00:07:18,150
and compliance with regulations.

180
00:07:18,150 --> 00:07:21,029
While internal assessments aim to identify and evaluate

181
00:07:21,029 --> 00:07:23,700
potential risk and vulnerabilities.

182
00:07:23,700 --> 00:07:25,920
The results of these audits and assessments

183
00:07:25,920 --> 00:07:28,470
should be used to make necessary improvements

184
00:07:28,470 --> 00:07:30,870
to the organization's security practices.

185
00:07:30,870 --> 00:07:32,490
Regular audits and assessments

186
00:07:32,490 --> 00:07:35,113
are crucial for maintaining a strong security posture

187
00:07:35,113 --> 00:07:38,970
and for ensuring ongoing compliance with internal policies

188
00:07:38,970 --> 00:07:41,643
and external regulatory requirements.

