

IT Security Compliance regulations and guidelines (GLBA, FFIEC, FDIC, NCUA, OCC, OTS) require an organization to conduct independent Audits of its Information Security Program. An IT Security Audit will verify the organization’s current security controls line up with the standards established by the FFIEC or Best Practices based on international standards such as ISO 27001, COBIT 4, etc.

The TraceSecurity IT Security Audit process meets this requirement by evaluating the effectiveness of and adherence to your organization’s Information Security controls as determined by your organization’s Risk Assessment or relevant regulations.
The process includes procedures to collect and examine data and practices which impact the effectiveness of the security program, and to help identify deficiency causes. Additionally, the examination process includes the ability to archive support data used to support audit conclusions with clear audit trails.
Some of the services in the TraceSecurity IT Security Audit include:
TraceSecurity Information Security Analysts (ISA) conduct the independent verification by reviewing the relevant documentation and performing interviews/walkthroughs.
Documentation includes the policies, procedures and checklists that define and/or support the IT controls. The interviews and walkthroughs, which are conducted with key personnel from the organization, are performed to validate adherence to the documented policies & procedures, as well as to corroborate the practices described during the interview process.
The IT Audit results are provided in an extensive report containing:

Although the IT Security Audit process should be a continuous function, many organizations find it cost-prohibitive to use third-party vendors to perform the necessary audits and manage the process on an ongoing basis. Plus, tapping in-house personnel may create an undue strain on internal resources.
That’s why TraceSecurity developed its IT Audit Manager solution which provides a seamless transition to an in-house managed IT Audit program. TraceSecurity’s IT Audit Manager helps automate the audit process so that an organization can effciently perform its own, on-demand IT Security Audit in a cost effective manner.
TraceSecurity IT Audit Manager is a specialized module contained within TraceSecurity’s Compliance Manager (TSCM), a comprehensive web-based software solution that provides access to a host of security compliance products organizations used to manage an ongoing security compliance program.
This solution provides the following benefits:
How does TraceSecurity IT Audit Manager enable an organization to perform regular IT audits?
With TraceSecurity IT Audit Manager, your organization can ensure that its internal IT Audit is performed using regulatory and Best Practices guidelines. These guidelines will help the organization effciently compile and evaluate the pertinent organizational data related to governance, controls, policies, and procedures to prepare for regulatory or independent IT audits. The business and regulatory standards are then analyzed against organizational standards and regulatory controls. The solution aligns closely with FFIEC and Best Practices Audits and radically simplies the audit process for the organization.
TraceSecurity IT Audit Manager empowers your IT staff to develop standard, repeatable IT Audit processes that are thorough, simple, and most importantly, accurate.
TraceSecurity IT Audit Manager offers many benefits to your organization: