To make sure an audit does what it's intended to do -- reduce risk to acceptable levels -- everyone involved must use the same words in the same way. You'd be amazed by how often that's not the case with words as seemingly basic as policy, standards and controls. That confusion results in a lot of head-scratching and wasted effort.
Here's list of some of the most misinterpreted words, along with explanations of what IT auditors mean when we say them.
- Policy
- Standards
- Controls