After completing check-out, your download will be available under MyISACA > Resources.
Strengthen biometric security with our updated audit program—assess risks, enhance resilience, and ensure compliance for secure, reliable biometric systems.
The primary objectives of the updated biometric audit program are to:
- Provide IT practitioners with new testing steps to independently assess biometric data security and protection risk, supply chain governance, and cloud and artificial intelligence (AI) based solutions deployed to support and effectively control biometric system data and equipment.
- Provide IT practitioners with additional cyber security, vulnerability management and resilience control evaluation techniques to help assure the IT function’s preparedness in the event of an intrusion or major failure of one or more biometric systems. Identify issues that may impact the security of the enterprise’s physical and logical security stance.
The audit program focuses on helping ensure enterprise policies, standards and procedures are in place to support secure biometric network architecture, resilience to major outages, intrusions or other failures, and the operational effectiveness of related security operations.
IT audit and assurance professionals are expected to customize this document to the environment in which they are performing an assurance process. This document is to be used as a review tool and starting point. It may be modified by the IT audit and assurance professional; it is not intended to be a checklist or questionnaire. It is assumed that the IT audit and assurance professional has the necessary subject matter expertise required to conduct the work and is supervised by a professional with the Certified Information Systems Auditor (CISA) designation and/or necessary subject matter expertise to adequately review the work performed.