Category: Basics

Basics | February 1, 2025

Planning an IT Audit for SOC 2 Controls: A Practical Approach

System and Organization Controls (SOC) 2 reports are critical for assessing the security, availability, processing integrity, confidentiality, and privacy of a service organization’s systems. Executing an IT audit for SOC […]


Share this:

Basics | January 7, 2025

Understanding Compensating Controls

In the world of IT Audit and Risk Management for any organization, controls play a crucial role in ensuring security, compliance, and operational efficiency. However, in certain situations, an organization […]


Share this:

Basics | January 4, 2025

COSO vs. COBIT Frameworks: Understanding the Differences

Frameworks help organizations establish strong internal controls, manage risks, and ensure compliance. Two widely used frameworks—COSO (Committee of Sponsoring Organizations of the Treadway Commission) and COBIT (Control Objectives for Information […]


Share this:

Basics | July 8, 2018

Differentiating Incident & Problem Management

Incident is a negative event or an event with negative outcomes. In general, Incident, Problem, are terms which are used interchangeably and in some places, to top up the confusion, […]


Share this:

Basics | June 27, 2018

Risk Treatment Methods

Risk – The potential for loss, damage or destruction of an asset as a result of a threat exploiting a vulnerability. The effect of risk can be positive or negative. […]


Share this:

Basics | June 25, 2018

Risk, Threat and Vulnerability

Risk, Threat and Vulnerabilities are the technical terms that are frequently used interchangeably. Although they are related to each other, they have different meanings. Consider a  situation like you are […]


Share this:

Basics | June 20, 2018

Business Continuity Terminologies – RTO, RPO & MAO

RTO – Recovery Time Objective This determines how quickly you need your systems back up and running following a disaster. In simple words, a time in future, at which your […]


Share this: