The National Audit Office (NAO) has published cyber security and information risk guidance for audit committees, after identifying a high incidence of access-control weaknesses and other issues in the course of preparing its reports
The watchdog published a report in September 2016 on protecting information across government, which found a lack of coherence between the various bodies responsible for governance, oversight and incident response.
In separate pieces of work on digital skills and online fraud, NAO noted the considerable challenge the public sector has in recruiting and retaining staff with the right experience and the lack of coordination across government and law enforcement agencies in dealing with criminal cyber activity.
The NAO says its financial audits routinely find weaknesses in financial system controls. The agency conducted detailed system audits on 30 bodies in 2017, of which 24 had access control weaknesses. It also frequently find issues in system change controls, business continuity, and third party oversight.
Audit committees should be scrutinising cyber security arrangements. This means that audit committees need to understand whether management is adopting a clear approach, and whether the organisation is complying with its rules and standards, and is adequately resourced for cyber security.
To avoid duplication, the NAO guide mirrors the government’s existing guidance, 10 Steps to cyber security, but has additional high level questions that may help audit committees address strategic issues before getting into areas of detail. It also lists some newer technology not covered before including the use of cloud services.
It provides a checklist of questions and issues covering the overall approach to cyber security and risk management; the capability needed to manage cyber security; specific aspects, such as information risk management, network security, user education, incident management, malware protection, monitoring, and home and mobile working; and related areas, such as developing new services or technology
Cyber security and information risk guidance for Audit Committees is here.
Report by Pat Sweet