After completing check-out, your download will be available under MyISACA > Resources.
One of the challenges that auditors face with compliance initiatives is providing assurance as expectations change. Data privacy is no exception. In the U.S., while some states have passed consumer privacy laws, remaining states have taken action ranging from creating data privacy task forces to having legislation in committee.1 Of the states who have already passed legislation, the California Consumer Privacy Act (CCPA) stands apart because of its potentially large scope: though the CCPA focuses on the data of California consumers, organizations anywhere in the world may need to be compliant with it.
CCPA’s broad scope has given this legislation visibility in the audit community. Given that, ISACA has written a CCPA audit program to provide management with an assessment of its CCPA policies and procedures and their operating effectiveness. Another objective of the CCPA audit program is to focus on CCPA governance and response mechanisms as well as supporting processes which can help manage the risk associated with noncompliance.
Accordingly, the audit program will assist auditors to:
- Evaluate the design and operating effectiveness of the entity’s practices and ongoing management of CCPA compliance.
- Identify control weaknesses that could result in increased use of unsanctioned CCPA solutions and corresponding higher likelihood unsanctioned solutions are undetected.
1 Noordyke, Mitchell; “US State Comprehensive Privacy Law Comparison” www.iapp.org; https://iapp.org/resources/article/state-comparison-table/