Project template
Security audit prep
The groundwork before an auditor or a customer's security review: policies, access, backups and evidence.
Week 1
Agree on the scope and the auditor
Day 4 · High priority
Which standard or questionnaire, which systems are in scope, and the dates.
Week 2
Gather the policies
Day 11 · High priority
Keep each policy as a doc, with its owner and the date it was last reviewed.
- Information security
- Access control
- Incident response
- Backups and recovery
- Vendor management
Week 3
Review who has access to what
Day 15 · High priority
Remove the accounts of people who left, and admin rights nobody uses.
Review vendors
Day 18 · Medium priority
Every service that holds our data or our customers' data, and what it holds.
Week 4
Test a restore from backup
Day 22 · High priority
Restore to a spare server, check the data is all there, and note how long it took.
Run an incident drill
Day 25 · Medium priority
Walk through a made-up incident, such as a lost laptop or a leaked password, using the incident response policy. Note what didn't work.
Week 5
Collect the evidence
Day 29 · High priority
Screenshots, exports and logs, one folder per control, named so the auditor can find them.
Week 6
Walk the auditor through it
Day 36 · High priority
The scope, the policies and where each piece of evidence is. Note every question that couldn't be answered on the spot.
Week 8
Fix what they found
Day 50 · Medium priority
One task per finding, each with an owner and a date.