Audits verify compliance. Poor preparation leads to findings and failed certifications.
Before the audit:
Review requirements and map controls to evidence.
Gather policies, diagrams, and configurations.
Conduct internal audits to find problems first.
Train staff who will be interviewed.
Common gaps:
- Outdated network diagrams
- Firewall rules without justification
- Access reviews not completed
During the audit: Assign a liaison, respond promptly, be honest about gaps.