After the audit is before the audit …
For many companies, the number of recurring audits and inspections is increasing and with it the time required. The supervision of the necessary audit activities (such as interviews) ties up the company’s own employees and sometimes massively disrupts general operations. These efforts also represent an internal cost factor in particular. While, in extreme cases, the auditors are all over the place, a look at the different audit schemes shows that there are many overlaps, particularly in the area of information security. This common core is based on a risk-based approach and a consideration of protection goals such as confidentiality, integrity and availability, as well as authenticity and non-repudiation. Information protection topics are grouped around this core, which include guidelines and personnel security, access and access regulations, but also the development and secure operation of systems, network security, secure configuration of systems, protection against malware, as well as monitoring and emergency management. One solution for reducing the time required is to combine checks in one audit. When putting together the team for such a combined audit, care is taken to ensure that the required test schemes are covered. Ideally, one auditor should cover several or even all the schemes relevant to the audit. By optimizing the planning of the audit sessions, the audit activities are carried out in just one audit period if possible and the collected results can be used in several procedures and reports. Our goal for your combined audit: one audit team – one audit period – all audits.