Skip to content

Project template

Security audit prep

The groundwork before an auditor or a customer's security review: policies, access, backups and evidence.

  1. Week 1

    • Agree on the scope and the auditor

      Day 4 · High priority

      Which standard or questionnaire, which systems are in scope, and the dates.

  2. Week 2

    • Gather the policies

      Day 11 · High priority

      Keep each policy as a doc, with its owner and the date it was last reviewed.

      • Information security
      • Access control
      • Incident response
      • Backups and recovery
      • Vendor management
  3. Week 3

    • Review who has access to what

      Day 15 · High priority

      Remove the accounts of people who left, and admin rights nobody uses.

    • Review vendors

      Day 18 · Medium priority

      Every service that holds our data or our customers' data, and what it holds.

  4. Week 4

    • Test a restore from backup

      Day 22 · High priority

      Restore to a spare server, check the data is all there, and note how long it took.

    • Run an incident drill

      Day 25 · Medium priority

      Walk through a made-up incident, such as a lost laptop or a leaked password, using the incident response policy. Note what didn't work.

  5. Week 5

    • Collect the evidence

      Day 29 · High priority

      Screenshots, exports and logs, one folder per control, named so the auditor can find them.

  6. Week 6

    • Walk the auditor through it

      Day 36 · High priority

      The scope, the policies and where each piece of evidence is. Note every question that couldn't be answered on the spot.

  7. Week 8

    • Fix what they found

      Day 50 · Medium priority

      One task per finding, each with an owner and a date.