After completing check-out, your download will be available under MyISACA > Resources.
Virtual Private Networks (VPNs) are relied on to give remote workers access to the corporate network securely. As the number of remote workers and the duration of remote work have increased (from remote working being temporary to potentially permanent), awareness of VPNs has grown. Now, with increased focus on cybersecurity, enterprises are questioning how the security of their VPNs. The concerns are justified, as some organizations had established VPNs quickly to meet an immediate need for remote work due to the global pandemic, and they may not have revisited their VPN controls. The speed with which some VPNs were implemented raised questions about configuration and other components
To address these concerns, ISACA offers a VPN Security Audit Program. This audit program provides control objectives, controls and testing for audit components, such as:
- Pre-Auditing Planning—terminology/technology, personnel, scope and documentation
- Governance and Oversight—oversight, policies and security awareness
- Implementation and Configuration—VPN architecture, configuration, client configuration and endpoint configuration
- Operations—policy implementation, data classification, VPN inventory, IT assets, VPN authentication, VPN access and vendor VPN access
- Maintenance and Monitoring—VPN activity logging and monitoring, patch management and VPN capacity planning integration of VPN technologies with the service desk
This audit program acknowledges the trending use of VPNs and provides auditors with a tool to evaluate VPNs to determine if the control environment is operating as designed.