The pain points I see most often are related to not having enough information. If you don't have the proper tools and visibility into your network, it's going to be very difficult to truly assess where things stand.
Another common gotcha with compliance audits is that they're vastly different from IT security assessments. You need to do both. I explain why our overdependence on "audits" can be bad for business in the following pieces:
Our dangerous overdependence on information technology auditsWhy do so many people buy into "checklist" audits?
Last Wiki Answer Submitted: January 28, 2013 8:49 pm by KevinBeaver10,785 pts.
All Answer Wiki Contributors: KevinBeaver10,785 pts.
If you live outside the United States, by submitting your email address you consent to having your personal data transferred to and processed in the United States.
We passed our last audit – I forget the name of the company, but they were not very thorough. There were holes in their audit that one could drive a truck through. I was contacted by the audit company and we discussed job opportunity, but when they told me how much they paid I learned why they were not very good.
We passed our last audit – I forget the name of the company, but they were not very thorough. There were holes in their audit that one could drive a truck through. I was contacted by the audit company and we discussed job opportunity, but when they told me how much they paid I learned why they were not very good.