SMotW #17: audit findings
Security Metric of the Week #17: n umber and severity of audit findings Our latest 'security metric of the week' builds on the following premises. Firstly, the number and severity of audit findings bears some relationship to the state or maturity of the organization's governance, risk, compliance and security arrangements, along with the number, quality, scope and depth of the audits. Secondly, si nce audits are invariably independent and formal, the number of audit findings is an objective, cheap and easy-to-obtain measure, as is the 'severity' ( or gravity or importance) provided findings are routinely rated/classified by the auditors, which they usually are. The severity of audit findings also helps focus management attention on the issues that really matter. [We are of course assuming that "audit finding" is a recognized term. Most if not all audit functions generate reports that identify and discuss discrete findings. Many also explici...