A&A-05: Is an audit management process defined and implemented to support audit planning,
risk analysis, security control assessments, conclusions, remediation schedules,
report generation, and reviews of past reports and supporting evidence?
Audit management process security should include:
a. Secure role-based access and authorization and secure communication and storage. b. Controls to protect audit data confidentiality, integrity, and availability. c. Periodic reporting, including issues and remediation plans per organizational requirements.
Control implemented
Control ownership
Description
Define and implement an Audit Management process to support audit planning, risk analysis, security control assessment, conclusion, remediation schedules, report generation, and review of past reports and supporting evidence.