Referring to The IIA’s Cybersecurity Topical Requirement and User Guide can help public-sector audit functions avoid this pitfall. These resources can help auditors assess cyber risk alongside other risks while ensuring cybersecurity is adequately covered across the three lines. As Elbagoury notes, collaboration between internal audit and the CISO is especially important.
In a LinkedIn blog post, “Cybersecurity Topical Requirement or Cybersecurity Internal Audit Standard,” Elbagoury writes, “The Cybersecurity Topical Requirement does not aim to turn the internal auditor into a technical expert, but rather to enable them to provide consistent and reliable professional assurance on how this risk is managed within the organization, based on clear and specific requirements.”
Elbagoury says he has found tremendous value in sharing the Topical Requirement and User Guide with his company’s CISO to prepare to coordinate future assessments. “He said they significantly enriched his point of view regarding cybersecurity, specifically regarding proper governance, risk management, and controls,” he says. “We now have a common language that we can share between ourselves and the client.”
A New Way of Thinking
The Pulse finding about public sector audit functions may point to a new, interconnected way of thinking about cyber risk, rather than a failure to prioritize it. As organizations increasingly view cybersecurity as an enterprisewide risk, internal audit must ensure it still receives sufficient attention. Integrating cyber risk is only effective if there is meaningful coverage.