What documentation do we need to have in place before an audit?

The specific documentation depends on the framework, but most audits require a System Security Plan (SSP) describing how each required control is implemented, a Plan of Action and Milestones (POA&M) addressing any known gaps, written security policies and procedures, evidence of employee security training and logs demonstrating that your controls are active and monitored. Documentation gaps are among the most common reasons organizations fail audits, and among the easiest to fix with proper preparation.

Share This
Related FAQs

Still Have Questions?

Send us a note or book a meeting to discuss your specific needs.