Description: This is a basic overview of my security audit workflow, it is designed to showcase my workflow pipeline for running security audits/risk assessments to be paired with developing risk management systems or general security plans for varying organizations and industries, it also pairs with certain compliance requirements like the IRS Written Information Security Plan for financial institutions.
Overview
What: This is my risk-based security audit/assessment workflow built from the NIST Cybersecurity Framework (2.0) and informed by NIST Risk Management Framework Principles.
Who: This is designed primarily for small businesses and firms (especially finance/accounting/tax practices). It is designed to compliment and pair with my IRS Written Information Security Plan (WISP) development workflow to bring my finance clients into compliance with regulatory standards.
Why: As stated above this pairs with my IRS WISP development process but also can standalone for any organization looking to audit/assess their current security posture (and hopefully lead to implementing security practices to mitigate the risks found in the assessment).
Purpose Of The Repo
-
End-to-end audit process
-
Risk identification and prioritization approach
-
Showcase the risk assessment workflow I use to conduct real-world assessments
Key Principle
This workflow focuses on identifying and prioritizing real-world business risks that can compromise compliance alignment and data security systems.