The cyber security audit, who performs it and how it runs
Audits are performed by managed security service providers holding the national security certificate, and for state bodies by the Information Systems Security Bureau. Riskoria does not hold that certificate and does not perform audits.
Who may perform an audit, and when
The auditor needs a certificate, and the entity needs to know on what deadline and at whose request.
Cyber security audits are performed by cyber security auditors, that is, by managed security service providers holding the national security certificate for auditing or an equivalent certificate under the relevant European certification scheme, under Article 32(2) of the Act. For state administration bodies and other state bodies the auditor is the Information Systems Security Bureau, under Article 32(3).
Riskoria does not hold that certificate and does not perform audits. We prepare you for one and help you find an auditor from the public register kept by the Information Systems Security Bureau, and keeping the two roles apart avoids a conflict of interest.
Essential entities must be audited at least once every two years, under Article 34(1) of the Act, and sooner if the competent authority requests it. Important entities carry out a self-assessment every two years, under Article 35(1), and an audit when the authority asks for one. The clock starts on the first working day after the deadline for implementing the measures expires.
How the audit runs
Six steps, from the announcement to the follow-up check on the fixes.
Announcement and scope agreement
The auditor announces the audit to the Information Systems Security Bureau at least ten working days before the date, and agrees the dates, the location and the subject with you. The announcement is the auditor’s obligation, not yours.
Audit plan and programme
The auditor prepares them before the work starts, aligned with the full scope of the control catalogue and with the thresholds of the evaluation framework. The plan is extended during the audit depending on what is found.
Review of documentation and records
The auditor asks for the documents and the records that go with them, usually before arriving. A document with no record of application is the first thing that shows.
Interviews with measure owners
The auditor talks to people, not only to paper, and puts the questions to the owner of the measure rather than to whoever wrote the document.
Sample testing of the evidence
What was said and written is checked against a sample of records. An area where a problem appears is usually explored further.
Findings, deadlines and the follow-up check
Non-conformities are given a deadline for correction and a follow-up check, and the audit report goes to the competent authority.
How the auditor scores
Documentation and implementation are scored separately, so good documentation does not rescue poor implementation, and neither does the reverse.
A control’s mark is the average of the documentation and implementation marks. A measure’s mark is the arithmetic mean of its sub-measure marks. A sub-measure passes only if both the individual threshold for each control and the sub-measure’s overall threshold are met, and some sub-measures use a strict overall threshold, where an average equal to the threshold does not pass.
What most often fails to count
Three patterns behind most of the evidence that does not hold up.
Frequently asked questions
Questions about the procedure itself, not about preparing for it.
How long does an audit take?
Depending on size, from a few days to two weeks on site, plus a documentation review beforehand and the findings afterwards.What happens with the findings?
Non-conformities are given a deadline for correction and a follow-up check. You submit the audit report to the competent authority without delay and no later than eight days from receipt, or immediately on receipt if the audit was carried out at that authority’s request.Is a finding a penalty?
It is not. A finding is not a penalty in itself, but an unresolved non-conformity becomes grounds for enforcement by the competent authority.Who bears the cost of the audit?
The entity being audited, under Article 34 of the Act.Where to go next
What the auditor scores, who is covered and how an entity gets ready is explained on these pages.
From the blog: the Cyber Security Act
The three latest texts on the Act, the measures and the audit.
The audit is performed by a certified auditor.
How an entity gets ready for one, step by step, is set out on the audit readiness page.
