ISACA has updated its Cybersecurity Audit Program, adapted from the National Institute of Standards and Technology (NIST) Cybersecurity Framework 2.0 (released in February 2024). New audit testing steps have been added to cover the risk strategy, supply chain risk management, and privacy cybersecurity controls introduced in the new NIST Govern function. In addition, a request list of documents, evidence, and other resources has been developed for auditors to leverage when engaging with auditees to substantiate the controls under review. Finally, the NIST CSF 2.0 Reference Tool implementation examples and COBIT 2019 references to key governance and management practices have been updated.
This audit program is redesigned to also provide auditors with a mechanism for documenting the conclusions drawn from the controls evaluation, along with a graphical summary of those results. Auditors are expected to customize this document to the environment in which they are performing an assurance process. It should be used as a review tool and starting point rather than a checklist or questionnaire. It is assumed that the auditor has the necessary subject matter expertise required to conduct the work and will be supervised by a professional with the Certified Information Systems Auditor (CISA) designation and/or necessary subject matter expertise to adequately review the work performed.