FreeToDoList

Cybersecurity Audit

Cybersecurity Audit

Step-by-step process to evaluate and improve your organization's cybersecurity posture

Technology

Template Items (17)

  • Initial cybersecurity assessment planning

    Start day

    #1
  • Define audit scope and objectives

    +2 days after start

    #2
  • Create inventory of IT assets

    +5 days after start

    #3
  • Review current security policies

    +8 days after start

    #4
  • Identify regulatory compliance requirements

    +11 days after start

    #5
  • Conduct vulnerability scanning

    +14 days after start

    #6
  • Perform network security assessment

    +17 days after start

    #7
  • Evaluate access control systems

    +20 days after start

    #8
  • Review password policies and practices

    +23 days after start

    #9
  • Assess data backup procedures

    +26 days after start

    #10
  • Review incident response plan

    +29 days after start

    #11
  • Evaluate employee security awareness

    +32 days after start

    #12
  • Check physical security controls

    +35 days after start

    #13
  • Compile audit findings

    +38 days after start

    #14
  • Prioritize security issues

    +41 days after start

    #15
  • Create remediation action plan

    +45 days after start

    #16
  • Present findings to stakeholders

    +50 days after start

    #17

Using this template will create a new list with all the items shown above. You can rename the list, and optionally add due dates counted from a start date you choose.

Who this is for

17 tasks covering a full security review of an organisation: scope, asset inventory, policy review, vulnerability scanning, access control, backups, incident response, and the reporting that turns findings into work. It's written for an internal audit — someone responsible for security at a small or mid-sized company — rather than a formal certification exercise, though it maps onto most frameworks well enough to prepare for one.

Inventory first, or the rest is guesswork

The asset inventory task looks like busywork and is the foundation of everything after it. You cannot assess what you don't know you have, and the gap between the systems people think are running and the systems actually running is where most real incidents start — the forgotten server, the contractor's account, the SaaS tool one team bought on a card.

Budget more time for this step than seems reasonable. It's normal for it to take longer than the scanning.

Findings without priorities are noise

A scan will return more issues than anyone can fix. The prioritisation task is what makes the audit useful: sorting by exploitability and blast radius rather than by the severity score the tool printed. A medium-severity flaw on an internet-facing system usually outranks a critical one on an isolated internal box.

Test the backups, don't just confirm they exist

The backup task means restoring something. An untested backup is a belief, not a control, and the restore is where people discover the retention window is shorter than they thought.

Timing

Six to eight weeks for a first audit. Turn on due dates — the offsets pace it so it doesn't stall after the scanning phase, which is where these usually die.