Auditing is the process of inspecting systems, accounts, and procedures to verify that policies are being followed and nothing has fallen out of alignment. This content covers the account management lifecycle, what to prioritize for regular audits, and the differences between internal self-assessments and third-party external audits.
Auditing
It's a nice idea that we could roll something out and it would be executed perfectly every time, that we would follow all the procedures exactly and nothing would fall through the cracks. But unfortunately that's not reality. Things always get out of sync, and we need something that keeps things in check. Well, that's what auditing does for us. Auditing allows us to identify when things are out of alignment, that things are out of sync.
The concept of auditing is very simple. It just means inspection. We're taking an inspection into things, and in this case right here we're inspecting to make sure that everything that we said we're going to do and that we've rolled out is actually being done.
Here's the life cycle of an account. When somebody is onboarded, they go through a provisioning process. They go through the maintenance of this account, where we do change management. And at some point in time there's a de-provisioning of the account.
Now, what happens is if we skip a step or do something wrong at the beginning, the user can oftentimes let us know and say, hey, I can't get into these systems, and then we go and correct that. So there's kind of a self adjustment that happens with that, because they just can't get access to certain things, and then they complain about it, and then we fix the issue.
But that same thing happens when they change positions. Maybe we give them permission for the new position, but we don't remove the permissions from the old position. So they've essentially got more access to things, everything that they had access to before plus everything new, and we haven't changed things properly.
Same thing with de-provisioning. When somebody leaves the company, hopefully we've got good processes in place to be able to decommission accounts and make sure that they're not able to still access our systems once they leave the company. But that doesn't always happen accurately or correctly, and so we need this auditing process to check all of these errors and what's happening along the way.
So we do auditing in all different areas, but let's continue with that example of account management. Maybe we get the list from HR and we compare it against our accounts every now and then. Maybe we do this on a monthly basis, maybe it's on a quarterly basis, maybe it's on a yearly basis. We also make sure those accounts have access to the proper resources, that they're not able to get to resources that they shouldn't get to.
So what is it that we should audit? Well, we have a ton of processes. We've rolled out a compliance process, a risk management process, an asset management process. We've rolled out all these processes, and then in each one of those processes there are errors that can happen. So at the very least we can audit any of these items, but the ones that are most critical. And then at the most, we could actually audit all of this and do all of the auditing, and some businesses will do that because they need to be very secure. But more often than not, we need to pick and choose what is going to be our most critical systems that we should audit on a regular basis.
Now, largely so far I just talked about self-audit, which is fair, that we need to do self-audits. We need to go and double check people's work, we need to check our work, we need to check other people's work and make sure that things are done correctly. So we just need to do some self assessments here.
Self-assessments are great because they're a lot less expensive and they can catch a lot of flaws or a lot of issues. But it's also difficult to be objective, and there's a bit of a conflict of interest. That is, I do things in a certain way, and so whatever is outside of my purview, I'm not going to be able to audit those correctly.
So sometimes it requires us to go outside and get a third party auditor, somebody to come in and help us audit. It still could be done internally, possibly with something like a committee. A committee might be in charge of auditing, or somebody from another department might be in charge of some of these audits. It's one reason why a security team that's separate from the rest of it is very helpful, because they can do this auditing and be detached from the actual IT department and the actual operations department.
But sometimes it's called for to do external audits, to have somebody come in and do an audit for you. A lot of times if you're working with vendors or customers or partners, especially customers, I've seen a lot of times where they've required the company that I've worked for to get a third-party audit. So there are times when customers may do an audit on a company, but more often than not I find that they require a third-party auditor to come in and audit us to make sure we're doing the right things.
Ultimately we probably are going to do both internal audits and external audits, that we're going to have some auditing that we're going to do internally and then also hire a third party to come in and make sure that we're doing things correct from an industry standard perspective.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →