After completing check-out, your download will be available under MyISACA > Resources.
Cybersecurity and audit practitioners may talk in terms of physical security being a part of cybersecurity or physical security being a subset of cybersecurity. While there may be differences of opinion in how physical security is defined in terms of cybersecurity, there is agreement that physical security may be overlooked while digital threats are considered from many perspectives. Cognizant of this potential neglect, ISACA has developed an audit program to enable auditors to effectively perform an assessment of controls within the physical and environmental security domain.
The audit program addresses the following areas: governance and oversight; planning and architecture; design and implementation (physical); design and implementation (environmental). By providing controls, control objectives, and testing in these areas, the audit program supports auditors in assessing controls implemented around physical assets and ultimately facilitates assurance around the adequacy and effectiveness of the implemented controls.