1
00:00:06,600 --> 00:00:08,040
- Welcome to lesson 27,

2
00:00:08,040 --> 00:00:11,640
explain types of audits and assessments.

3
00:00:11,640 --> 00:00:15,240
In 27.1 we're gonna focus in on audits,

4
00:00:15,240 --> 00:00:16,073
but we're gonna start

5
00:00:16,073 --> 00:00:19,590
with a general discussion
about security assessments.

6
00:00:19,590 --> 00:00:22,800
An information security
assessment is a process

7
00:00:22,800 --> 00:00:26,910
of determining how effectively
the entity being evaluated

8
00:00:26,910 --> 00:00:29,430
meets specific criteria.

9
00:00:29,430 --> 00:00:33,600
Now, there are two approaches,
examination and testing.

10
00:00:33,600 --> 00:00:35,310
Examination is the process

11
00:00:35,310 --> 00:00:38,430
of interviewing, reviewing,
inspecting, studying

12
00:00:38,430 --> 00:00:42,690
and observing to facilitate
understanding or comparing

13
00:00:42,690 --> 00:00:46,500
to standards or baselines
or to obtain evidence.

14
00:00:46,500 --> 00:00:49,290
It's often referred to
as a passive approach

15
00:00:49,290 --> 00:00:52,620
because we're not interacting
necessarily with systems.

16
00:00:52,620 --> 00:00:55,320
Now, audit is an examination

17
00:00:55,320 --> 00:00:57,030
so we'll be talking about audit shortly

18
00:00:57,030 --> 00:01:00,720
and that's gonna be a good
example of doing an examination.

19
00:01:00,720 --> 00:01:04,350
Testing is the process
of exercising objects

20
00:01:04,350 --> 00:01:07,980
under specified conditions
to compare actual

21
00:01:07,980 --> 00:01:09,870
and expected behavior.

22
00:01:09,870 --> 00:01:13,200
A good example of testing
would be penetration.

23
00:01:13,200 --> 00:01:15,510
Testing is generally
considered intrusive, right?

24
00:01:15,510 --> 00:01:17,520
Because we're interacting with the system.

25
00:01:17,520 --> 00:01:19,740
And after we do our lesson about audit

26
00:01:19,740 --> 00:01:22,593
we actually have two lessons
about penetration testing.

27
00:01:25,410 --> 00:01:26,760
Now, assurance is the measure

28
00:01:26,760 --> 00:01:29,730
of confidence that intended controls,

29
00:01:29,730 --> 00:01:33,900
plans and processes are
effective in their application.

30
00:01:33,900 --> 00:01:35,400
The objective of an audit

31
00:01:35,400 --> 00:01:37,890
is to provide independent assurance

32
00:01:37,890 --> 00:01:39,060
based on evidence,

33
00:01:39,060 --> 00:01:41,400
and there are some really key words there.

34
00:01:41,400 --> 00:01:43,650
Independent and evidence.

35
00:01:43,650 --> 00:01:44,940
Auditors are bound

36
00:01:44,940 --> 00:01:48,360
by auditing standards that
require their independence

37
00:01:48,360 --> 00:01:52,800
and all of their conclusions
are based upon evidence.

38
00:01:52,800 --> 00:01:55,050
The audit evidence is
all of the information

39
00:01:55,050 --> 00:01:57,090
whether obtained from the audit procedures

40
00:01:57,090 --> 00:01:59,760
or other sources that's
used by the auditor

41
00:01:59,760 --> 00:02:01,860
in arriving at the conclusion

42
00:02:01,860 --> 00:02:04,473
on which the auditor's opinion is based.

43
00:02:05,670 --> 00:02:09,720
Before an audit commences,
there will be an audit plan.

44
00:02:09,720 --> 00:02:12,300
The audit plan is a high level description

45
00:02:12,300 --> 00:02:17,010
of the audit work to be performed
in a specific timeframe.

46
00:02:17,010 --> 00:02:20,100
Now, the plan may include
objectives, scope,

47
00:02:20,100 --> 00:02:21,870
resource requirements,

48
00:02:21,870 --> 00:02:25,710
intended evidence collection
techniques, target audience

49
00:02:25,710 --> 00:02:27,720
and reporting expectations.

50
00:02:27,720 --> 00:02:29,640
Now, the audit plan will be documented

51
00:02:29,640 --> 00:02:32,070
in what is called an engagement letter.

52
00:02:32,070 --> 00:02:34,620
Now, the final audience for audit results

53
00:02:34,620 --> 00:02:38,643
will either be executive or
maybe a board audit committee.

54
00:02:40,740 --> 00:02:43,200
So let's talk about audit focus.

55
00:02:43,200 --> 00:02:45,720
An audit might focus on compliance,

56
00:02:45,720 --> 00:02:49,560
meaning are we meeting
applicable laws, regulations,

57
00:02:49,560 --> 00:02:53,043
contracts and or industry
standards and guidelines?

58
00:02:54,210 --> 00:02:56,970
An audit focus might
be security and privacy

59
00:02:56,970 --> 00:02:58,890
which is about achieving
appropriate levels

60
00:02:58,890 --> 00:03:03,483
of confidentiality, integrity,
availability, and privacy.

61
00:03:04,350 --> 00:03:06,780
An audit could be on internal controls

62
00:03:06,780 --> 00:03:09,240
and that's the evaluation of the design

63
00:03:09,240 --> 00:03:13,320
of controls and assessment of
the operational effectiveness

64
00:03:13,320 --> 00:03:15,453
and efficiency of those controls.

65
00:03:17,010 --> 00:03:20,610
Or the audit focus could be
alignment to assure alignment

66
00:03:20,610 --> 00:03:24,303
with organizational and
or control objectives.

67
00:03:26,370 --> 00:03:29,310
Now, very often in an
audit, sampling is used.

68
00:03:29,310 --> 00:03:32,220
Sampling is used to infer characteristics

69
00:03:32,220 --> 00:03:33,600
about the population

70
00:03:33,600 --> 00:03:36,600
based on the characteristics
of the sample.

71
00:03:36,600 --> 00:03:38,700
Evidence sampling is applying a procedure

72
00:03:38,700 --> 00:03:41,790
to less than 100% of the population.

73
00:03:41,790 --> 00:03:43,320
Now, sampling rule of thumb

74
00:03:43,320 --> 00:03:44,940
how many samples you take

75
00:03:44,940 --> 00:03:47,700
is often based on professional judgment,

76
00:03:47,700 --> 00:03:49,320
but there are some guidelines.

77
00:03:49,320 --> 00:03:51,360
An audit of a low risk target

78
00:03:51,360 --> 00:03:53,640
generally requires a small sample.

79
00:03:53,640 --> 00:03:55,770
An audit of a high risk target

80
00:03:55,770 --> 00:03:59,853
generally requires a large
sample or even a complete check.

81
00:04:01,050 --> 00:04:04,920
Now, in scenarios where there
are really strong controls

82
00:04:04,920 --> 00:04:07,260
that might require just a small sample.

83
00:04:07,260 --> 00:04:09,960
And in scenarios where
there is weak controls

84
00:04:09,960 --> 00:04:12,810
those will generally
require a large sample.

85
00:04:12,810 --> 00:04:16,053
But again, this will be at
the discretion of the auditor.

86
00:04:18,390 --> 00:04:20,400
Now, at the conclusion of an audit,

87
00:04:20,400 --> 00:04:23,460
after the audit work has
all been done and analyzed,

88
00:04:23,460 --> 00:04:25,740
the auditor will issue an opinion.

89
00:04:25,740 --> 00:04:28,230
Now, there are four audit opinions.

90
00:04:28,230 --> 00:04:32,700
Unqualified, qualified,
adverse, and disclaimer.

91
00:04:32,700 --> 00:04:34,230
And no, unqualified doesn't mean

92
00:04:34,230 --> 00:04:36,210
that the auditor was unqualified.

93
00:04:36,210 --> 00:04:37,830
So what does it mean?

94
00:04:37,830 --> 00:04:39,720
An unqualified opinion is rendered

95
00:04:39,720 --> 00:04:42,660
when the auditor doesn't have
any significant reservations.

96
00:04:42,660 --> 00:04:45,300
That would be an unqualified opinion.

97
00:04:45,300 --> 00:04:47,070
A qualified opinion is rendered

98
00:04:47,070 --> 00:04:51,450
when there are some minor
deviations or scope limitations.

99
00:04:51,450 --> 00:04:54,030
An adverse opinion is
rendered when the target

100
00:04:54,030 --> 00:04:57,270
is not in conformance with
the control objectives

101
00:04:57,270 --> 00:05:01,230
or when the evidence is
misleading or misstated.

102
00:05:01,230 --> 00:05:04,950
And an audit examination report
can also have a disclaimer

103
00:05:04,950 --> 00:05:08,160
that the auditor was not
able to render an opinion

104
00:05:08,160 --> 00:05:10,743
due to whatever the
named circumstances are.

105
00:05:12,420 --> 00:05:14,610
An audit framework is a structured

106
00:05:14,610 --> 00:05:16,560
and systematic approach that are used

107
00:05:16,560 --> 00:05:18,870
by auditors to plan, execute

108
00:05:18,870 --> 00:05:21,300
and report on an audit engagement.

109
00:05:21,300 --> 00:05:23,550
Now, audit frameworks
are typically developed

110
00:05:23,550 --> 00:05:26,370
by auditing standard setting bodies.

111
00:05:26,370 --> 00:05:28,350
Now, there are two very common types

112
00:05:28,350 --> 00:05:30,270
of audits you wanna be familiar with.

113
00:05:30,270 --> 00:05:34,380
First is the ISACA
COBIT 5 audit framework.

114
00:05:34,380 --> 00:05:36,390
Second is the AICPA.

115
00:05:36,390 --> 00:05:38,220
That stands for the American Institute

116
00:05:38,220 --> 00:05:40,320
of Certified Public Accountants.

117
00:05:40,320 --> 00:05:43,560
Now, they have a framework
known as the statement

118
00:05:43,560 --> 00:05:47,310
on standards for attestation
engagements number 18.

119
00:05:47,310 --> 00:05:48,450
That's a mouthful.

120
00:05:48,450 --> 00:05:52,890
What we really call it all
the time is an SSAE18 report.

121
00:05:52,890 --> 00:05:55,590
Now, why do you need to
know about SSAE18 report?

122
00:05:55,590 --> 00:05:59,250
Well, besides for your
examination, it's probably the type

123
00:05:59,250 --> 00:06:02,580
of audit report that you
will most interact with.

124
00:06:02,580 --> 00:06:05,130
It's a type of report
that is generally issued

125
00:06:05,130 --> 00:06:08,910
by a technology company to prove the type

126
00:06:08,910 --> 00:06:10,740
of controls it has in place

127
00:06:10,740 --> 00:06:14,250
and it's the one that we'll
use in our due diligence.

128
00:06:14,250 --> 00:06:18,540
So let's take a look at an SSAE18 report.

129
00:06:18,540 --> 00:06:20,400
Well, there are actually three versions

130
00:06:20,400 --> 00:06:25,400
of an SSAE18, a SOC1, a SOC2, and a SOC3.

131
00:06:26,623 --> 00:06:29,250
A SOC1 is a report on controls relevant

132
00:06:29,250 --> 00:06:32,100
to a user entity's financial statements

133
00:06:32,100 --> 00:06:33,720
and there's an agreed upon scope

134
00:06:33,720 --> 00:06:36,780
between the audit firm and the
organization being audited.

135
00:06:36,780 --> 00:06:39,480
It's not really relevant
to us unless perhaps

136
00:06:39,480 --> 00:06:41,910
you have some financial
compliance requirements

137
00:06:41,910 --> 00:06:43,650
like Sarbanes Oxley.

138
00:06:43,650 --> 00:06:46,503
It's also what we used
to call a SAS 70 report.

139
00:06:47,430 --> 00:06:51,270
A SOC2 is the one that we
really wanna be working with.

140
00:06:51,270 --> 00:06:53,100
A SOC2 is based upon what's known

141
00:06:53,100 --> 00:06:56,430
as a TSP, the trust services principles

142
00:06:56,430 --> 00:06:58,440
and that reports on controls intended

143
00:06:58,440 --> 00:07:01,260
to mitigate risk related to security,

144
00:07:01,260 --> 00:07:04,440
availability, processing integrity,

145
00:07:04,440 --> 00:07:07,590
confidentiality, or privacy.

146
00:07:07,590 --> 00:07:10,290
Now, what's really interesting
about the SOC2 report though

147
00:07:10,290 --> 00:07:12,420
is it doesn't necessarily cover all five

148
00:07:12,420 --> 00:07:13,710
of those categories.

149
00:07:13,710 --> 00:07:16,410
The organization that's
being audited gets to say

150
00:07:16,410 --> 00:07:19,260
these are the categories
I wanna be audited on,

151
00:07:19,260 --> 00:07:22,890
maybe security and availability.

152
00:07:22,890 --> 00:07:25,600
But perhaps what you really
care about is privacy.

153
00:07:25,600 --> 00:07:27,990
Well, if the report
didn't cover that category

154
00:07:27,990 --> 00:07:30,060
it's not gonna be useful to you.

155
00:07:30,060 --> 00:07:31,830
The organization chooses a category

156
00:07:31,830 --> 00:07:32,940
and you always wanna be cognizant

157
00:07:32,940 --> 00:07:35,070
of those categories when
you're reading the report

158
00:07:35,070 --> 00:07:36,570
but they don't get to choose

159
00:07:36,570 --> 00:07:38,790
what controls are going to be looked at.

160
00:07:38,790 --> 00:07:40,260
The controls that are gonna be looked at

161
00:07:40,260 --> 00:07:42,570
are determined by the auditor.

162
00:07:42,570 --> 00:07:44,040
So they can choose the category

163
00:07:44,040 --> 00:07:46,470
but they can't control the the scope

164
00:07:46,470 --> 00:07:49,080
of what is going to be examined.

165
00:07:49,080 --> 00:07:52,680
Now, a SOC2 report, generally
you'll have to sign an NDA

166
00:07:52,680 --> 00:07:55,380
before it'll be issued to
you because there's a lot

167
00:07:55,380 --> 00:07:59,160
of proprietary information
about the organization

168
00:07:59,160 --> 00:08:02,490
and about whatever the
service or the application is

169
00:08:02,490 --> 00:08:05,430
That is the target of the audit

170
00:08:05,430 --> 00:08:08,190
as well as all of the
testing will be detailed

171
00:08:08,190 --> 00:08:10,230
and the results will be detailed.

172
00:08:10,230 --> 00:08:11,760
So you get a lot of information.

173
00:08:11,760 --> 00:08:13,260
It's really comprehensive.

174
00:08:13,260 --> 00:08:14,850
It's incredibly useful

175
00:08:14,850 --> 00:08:18,963
as long as it covers the
categories that you care about.

176
00:08:19,800 --> 00:08:22,170
Now, a SOC3 is very similar to a SOC2.

177
00:08:22,170 --> 00:08:25,230
It's based on the TSP, the
trust services principle

178
00:08:25,230 --> 00:08:27,720
but it doesn't have any
proprietary information.

179
00:08:27,720 --> 00:08:29,340
So no NDA required

180
00:08:29,340 --> 00:08:32,910
but it also doesn't detail
any of the testing performed.

181
00:08:32,910 --> 00:08:35,040
It's really a marketing piece designed

182
00:08:35,040 --> 00:08:36,660
for public distribution.

183
00:08:36,660 --> 00:08:40,440
So a SOC2 is the one that
we really wanna be using.

184
00:08:40,440 --> 00:08:42,180
And then there are two types.

185
00:08:42,180 --> 00:08:44,760
There's a type one and a type two.

186
00:08:44,760 --> 00:08:48,720
A type one reports on
controls placed in operation

187
00:08:48,720 --> 00:08:50,460
as of a point in time.

188
00:08:50,460 --> 00:08:53,850
So it's an evaluation of
design and implementation

189
00:08:53,850 --> 00:08:55,260
but not operating effectiveness.

190
00:08:55,260 --> 00:08:56,280
It's not how well it works,

191
00:08:56,280 --> 00:08:59,670
it's just that on this
date, the control was there.

192
00:08:59,670 --> 00:09:01,560
Now we'll know it is a type one

193
00:09:01,560 --> 00:09:04,890
because the cover of a report
will show an as of date.

194
00:09:04,890 --> 00:09:07,710
So maybe it says as of July one

195
00:09:07,710 --> 00:09:10,530
as of January one, but they, as of date,

196
00:09:10,530 --> 00:09:12,930
we'll say on that date,
those controls were there.

197
00:09:12,930 --> 00:09:14,250
We don't know how well they worked

198
00:09:14,250 --> 00:09:16,300
but we know they were there on that date.

199
00:09:17,340 --> 00:09:20,790
A type two reports on
design, implementation

200
00:09:20,790 --> 00:09:23,670
and operating effectiveness
over a period of time.

201
00:09:23,670 --> 00:09:25,890
Now, generally 6 months or 12 months

202
00:09:25,890 --> 00:09:29,520
and that includes tests
of operating effectiveness

203
00:09:29,520 --> 00:09:31,680
and results over a period of time

204
00:09:31,680 --> 00:09:35,040
with a very strong emphasis
on evidential matter.

205
00:09:35,040 --> 00:09:36,990
Now, how will you know
you're getting a type two?

206
00:09:36,990 --> 00:09:39,300
Because the cover of the
report will show a time period

207
00:09:39,300 --> 00:09:40,680
of generally 6 or 12 months.

208
00:09:40,680 --> 00:09:43,800
So it might say January
one through December 31st

209
00:09:43,800 --> 00:09:46,860
or it might say July one
through December 31st.

210
00:09:46,860 --> 00:09:50,520
But it will have that period
of time right on the cover.

211
00:09:50,520 --> 00:09:52,560
So best of all worlds, what do we get?

212
00:09:52,560 --> 00:09:54,423
A SOC2, type two.

213
00:09:55,350 --> 00:09:58,410
And that, my friends, brings
us to a three second challenge.

214
00:09:58,410 --> 00:09:59,243
Are you ready?

215
00:09:59,243 --> 00:10:00,690
Five questions, three seconds each.

216
00:10:00,690 --> 00:10:01,523
Let's do it.

217
00:10:02,490 --> 00:10:03,660
This process results

218
00:10:03,660 --> 00:10:07,050
in independent evidence-based assurance.

219
00:10:07,050 --> 00:10:09,420
1, 2, 3.

220
00:10:09,420 --> 00:10:10,893
That's gonna be audit.

221
00:10:12,150 --> 00:10:13,590
Number two, this type

222
00:10:13,590 --> 00:10:15,570
of audit compares the control environment

223
00:10:15,570 --> 00:10:18,753
to establish policies,
standards, or rules.

224
00:10:20,280 --> 00:10:22,560
1, 2, 3.

225
00:10:22,560 --> 00:10:24,360
This is gonna be a compliance audit.

226
00:10:24,360 --> 00:10:27,930
Are we in compliance with
those policies of standards,

227
00:10:27,930 --> 00:10:30,720
those rules or those regulations?

228
00:10:30,720 --> 00:10:31,710
Number three,

229
00:10:31,710 --> 00:10:35,223
techniques used to infer
characteristics of a population.

230
00:10:36,330 --> 00:10:37,773
1, 2, 3.

231
00:10:38,940 --> 00:10:40,443
And that's gonna be sampling.

232
00:10:42,300 --> 00:10:43,440
Number four,

233
00:10:43,440 --> 00:10:45,960
an audit opinion rendered when the auditor

234
00:10:45,960 --> 00:10:49,053
does not have any
significant reservations.

235
00:10:50,160 --> 00:10:51,513
1, 2, 3.

236
00:10:52,680 --> 00:10:55,350
And that's gonna be an unqualified opinion

237
00:10:55,350 --> 00:10:57,963
which always sounds weird,
but that's what it is.

238
00:10:59,130 --> 00:11:02,190
And number five, audit assessment standard

239
00:11:02,190 --> 00:11:03,450
most commonly used

240
00:11:03,450 --> 00:11:06,813
by technology oriented
service organizations.

241
00:11:07,800 --> 00:11:08,633
You know this.

242
00:11:08,633 --> 00:11:10,500
1, 2, 3.

243
00:11:10,500 --> 00:11:13,893
This is an SSAE18 SOC2.

244
00:11:15,330 --> 00:11:20,010
Alright, let's take a look
at our security-in-action.

245
00:11:20,010 --> 00:11:21,710
This one's about an audit dispute.

246
00:11:22,740 --> 00:11:24,780
You brought in an outside audit firm

247
00:11:24,780 --> 00:11:28,140
to conduct an information
security internal controls audit

248
00:11:28,140 --> 00:11:30,540
for a recently acquired division.

249
00:11:30,540 --> 00:11:33,270
Throughout the audit, the
target division manager

250
00:11:33,270 --> 00:11:35,700
has been really difficult to work with.

251
00:11:35,700 --> 00:11:37,890
And during the exit
interview of the audit,

252
00:11:37,890 --> 00:11:40,350
he questioned the auditor's competency.

253
00:11:40,350 --> 00:11:41,760
And at the management meeting

254
00:11:41,760 --> 00:11:45,150
he hotly disputed the audit findings.

255
00:11:45,150 --> 00:11:47,760
How are we gonna handle this situation?

256
00:11:47,760 --> 00:11:48,960
So a quick recap.

257
00:11:48,960 --> 00:11:51,360
We've brought in this outside audit firm.

258
00:11:51,360 --> 00:11:53,520
They're gonna conduct
an information security

259
00:11:53,520 --> 00:11:55,260
internal controls audit

260
00:11:55,260 --> 00:11:58,080
for a division that we recently acquired

261
00:11:58,080 --> 00:12:00,900
and the target division manager

262
00:12:00,900 --> 00:12:03,240
really, really difficult to work with.

263
00:12:03,240 --> 00:12:04,530
And then the exit interview

264
00:12:04,530 --> 00:12:06,810
that was when our auditors
were leaving, you know,

265
00:12:06,810 --> 00:12:09,000
he questioned the auditor's competency.

266
00:12:09,000 --> 00:12:10,920
It's like, you don't know what
you're doing, kind of thing.

267
00:12:10,920 --> 00:12:13,110
And at the follow-up management meeting

268
00:12:13,110 --> 00:12:16,680
he hotly disputed the audit findings.

269
00:12:16,680 --> 00:12:18,240
So how are we gonna handle this situation?

270
00:12:18,240 --> 00:12:19,290
What do you think?

271
00:12:19,290 --> 00:12:22,223
Go ahead and put me on pause
and think about your response.

272
00:12:27,000 --> 00:12:29,130
Well, you may wanna start
with ask the manager

273
00:12:29,130 --> 00:12:32,670
to explain the dispute and
the competency concerns.

274
00:12:32,670 --> 00:12:33,720
Give them some agency.

275
00:12:33,720 --> 00:12:35,070
Let them, you know,

276
00:12:35,070 --> 00:12:38,310
explain why they're so
concerned about this,

277
00:12:38,310 --> 00:12:40,510
or why they disagree so vehemently

278
00:12:41,820 --> 00:12:44,220
that if there is sufficient cause

279
00:12:44,220 --> 00:12:46,470
we should revalidate the audit testing

280
00:12:46,470 --> 00:12:49,980
and the sampling techniques
as well as the evidence

281
00:12:49,980 --> 00:12:53,163
to ensure that it does
support the audit findings.

282
00:12:54,360 --> 00:12:57,690
Now, if after reevaluating
and maybe retesting

283
00:12:57,690 --> 00:13:00,060
or choosing not to,
depending on what you do,

284
00:13:00,060 --> 00:13:02,550
there are still unsettled disagreements.

285
00:13:02,550 --> 00:13:04,350
The issue should be included

286
00:13:04,350 --> 00:13:07,180
in the final report that
will go to an audit committee

287
00:13:08,550 --> 00:13:10,980
and having to deal with
these difficult situations

288
00:13:10,980 --> 00:13:15,150
but finding our way
through security-in-action.

289
00:13:15,150 --> 00:13:16,860
Alright, there's your word cloud.

290
00:13:16,860 --> 00:13:18,510
Make sure you know it all

291
00:13:18,510 --> 00:13:20,430
before you move on to our next two lessons

292
00:13:20,430 --> 00:13:22,770
where we're gonna be talking
about penetration testing.

293
00:13:22,770 --> 00:13:23,720
I'll see you there.
