CORAA
Resources · Internal Audit Cybersecurity

Cybersecurity internal audit resilience.

Cybersecurity is no longer only an ITGC appendix. Internal audit should test whether the organisation can prevent, detect, escalate and recover from cyber events, and whether management can evidence the decisions made during an incident.

Open ITGC checklistOpen monitoring rules
Direct answer

What a cybersecurity internal audit checklist covers checklist

A cybersecurity internal audit checklist should test ransomware readiness, identity and privileged access, incident response, vulnerability remediation, logging, cloud/SaaS configuration, third-party cyber access and personal-data breach evidence. The output should be an evidence file, exception register, remediation tracker and escalation view, not a legal conclusion on reportability.

Best used for
  • Annual internal audit planning
  • Ransomware or incident readiness reviews
  • Cloud, vendor-access and DPDP-facing evidence checks
Downloads

Cyber resilience audit pack workbook

Download the Excel/PDF pack for risk areas, controls, tests, evidence, monitoring rules, reporting fields and escalation routes.

Risk areas

Eight areas to test coverage

Ransomware readiness

Risk: Critical operations stop because recovery plans, immutable backups, endpoint controls or crisis decisions were never tested together.

Controls
  • Ransomware playbook
  • Immutable/offline backup
  • Endpoint protection
  • Tabletop exercise
Tests
  • Inspect ransomware scenario playbook and decision owners
  • Check whether backup copies are isolated from production credentials
  • Review last tabletop exercise actions and closure
  • Trace one critical system to RTO/RPO and restoration evidence
Evidence

Ransomware playbook, BCP/DR plan, backup architecture, restoration test, tabletop minutes, action tracker and crisis RACI.

Identity and privileged access

Risk: Attackers or insiders use active, privileged, stale or shared accounts to change data, deploy scripts or exfiltrate information.

Controls
  • MFA for privileged access
  • Privileged access management
  • Leaver disablement
  • Periodic access review
Tests
  • Match active privileged users to approved owner list
  • Test terminated users and role changes for timely removal
  • Review shared/service accounts and break-glass logs
  • Check MFA exceptions and compensating controls
Evidence

Privileged user list, IAM/PAM exports, HR leaver list, MFA exception register, access review sign-off and activity logs.

Incident response and reporting

Risk: Incidents are detected late, escalated informally, or reported without reliable timeline, evidence owner and decision trail.

Controls
  • Incident classification
  • Escalation matrix
  • Forensic evidence preservation
  • Regulatory notification workflow
Tests
  • Inspect incident register completeness and severity mapping
  • Trace selected incidents from alert to closure
  • Check evidence preservation and chain-of-custody steps
  • Review whether CERT-In, customer, regulator or Board reporting assessment was documented where relevant
Evidence

Incident register, SIEM/security tickets, severity matrix, response timeline, legal/regulatory assessment, communications log and lessons-learned report.

Vulnerability and patch management

Risk: Known vulnerabilities remain open on internet-facing or critical systems because ownership, risk acceptance or remediation evidence is weak.

Controls
  • Asset inventory
  • Vulnerability scan cadence
  • Patch SLA
  • Exception approval
Tests
  • Compare scan scope to asset inventory and cloud inventory
  • Review critical/high vulnerabilities against SLA
  • Inspect exceptions for owner, expiry and compensating controls
  • Trace sampled patches to deployment evidence
Evidence

Asset register, vulnerability scan report, patch dashboard, exception register, change tickets and remediation evidence.

Logging and security monitoring

Risk: Suspicious activity is not detected or investigated because logs are missing, not retained or not reviewed by accountable owners.

Controls
  • Critical log source inventory
  • SIEM alert triage
  • Log retention
  • Escalation for high alerts
Tests
  • Map critical systems to available log sources
  • Sample alerts for triage, owner and closure
  • Check retention period and tamper protection
  • Review alert backlog and false-positive tuning
Evidence

Log-source inventory, SIEM dashboard, alert tickets, retention settings, reviewer sign-off and tuning change log.

Cloud and SaaS configuration

Risk: Cloud storage, SaaS roles, API keys or admin settings expose data or allow unauthorized changes outside normal ITGC controls.

Controls
  • Cloud security baseline
  • SaaS admin review
  • API key rotation
  • Configuration drift monitoring
Tests
  • Inspect admin-role exports for critical SaaS applications
  • Review public storage and external-sharing exceptions
  • Check API/service-key inventory and rotation
  • Compare cloud posture findings with remediation tracker
Evidence

Cloud posture report, SaaS admin export, external-sharing report, API key inventory, configuration baseline and exception closure file.

Third-party cyber access

Risk: Vendors, implementation partners or outsourced providers retain access or host data without current security, SLA, BCP and exit evidence.

Controls
  • Vendor criticality rating
  • Access recertification
  • Security clauses
  • Incident and BCP obligations
Tests
  • Identify vendors with system/admin/data access
  • Check access recertification and termination evidence
  • Review contract clauses for incident notification and audit rights
  • Inspect SOC/ISO/security evidence where relied upon
Evidence

Vendor inventory, access list, contract/security addendum, SLA report, assurance report, incident notice clause and exit plan.

Privacy and personal-data breach evidence

Risk: Personal data exposure is not assessed, contained or documented consistently with DPDP-facing obligations and customer/regulator expectations.

Controls
  • Personal-data inventory
  • Breach assessment workflow
  • Data retention controls
  • DPO/legal escalation
Tests
  • Map systems holding personal data to owners and processors
  • Review breach assessment fields and decision evidence
  • Check deletion/retention exceptions
  • Trace selected access/export events to business justification
Evidence

Data inventory, processor list, breach assessment memo, retention/deletion logs, access/export logs and legal/DPO review evidence.

Continuous monitoring

Cyber rules internal audit can monitor signals

DomainRuleSource dataCadence
IdentityPrivileged account created or reactivated without approved ticketIAM/PAM export, HR data, ticketing systemDaily or weekly
IdentityTerminated employee still active in VPN, ERP, email, cloud or SaaS admin roleHR leaver list, IAM, VPN, ERP, SaaS exportsDaily
Incident responseHigh-severity alert open beyond escalation SLA or closed without owner conclusionSIEM, SOC tickets, incident registerDaily
BackupsCritical backup job failed or restoration test overdue for a Tier 1 systemBackup console, DR calendar, asset criticality listDaily/weekly
VulnerabilityCritical vulnerability past remediation SLA without risk acceptanceScanner, asset inventory, patch tracker, exception registerWeekly
Cloud/SaaSPublic sharing, external admin or stale API key on critical systemCloud posture tool, SaaS admin export, key inventoryWeekly
Vendor accessVendor user active after contract end, project closure or last-login inactivity thresholdVendor register, IAM, project closure, login logsWeekly/monthly
PrivacyBulk export of personal data outside approved role or ticketDLP/export logs, HR/customer systems, ticketing workflowDaily/weekly
Reporting

What the cyber workpaper should retain evidence

Scenario and asset

Name the ransomware, access, incident, cloud, vendor or privacy scenario and the affected system/business process.

Control objective

State what the control should prevent, detect, recover or evidence.

Evidence source

Retain report parameters, export date, system owner, screenshots/logs and control totals where applicable.

Exception severity

Rate exposure using business criticality, data sensitivity, exploitability, recurrence and compensating controls.

Regulatory assessment

Document whether CERT-In, DPDP, sector regulator, customer or Board reporting was assessed; do not present legal advice as audit conclusion.

Remediation route

Owner, target date, interim mitigation, risk acceptance, retest plan and committee escalation where relevant.

Sources

Authority anchors used anchors

IIA Risk in Focus 2026IIA GTAG: Assessing Cybersecurity RiskCERT-In Directions under section 70B of the IT ActMeitY Digital Personal Data Protection Rules, 2025

This resource is an internal audit planning and evidence checklist. It does not replace legal, regulatory, forensic, cyber incident response or statutory audit conclusions.

Related resources

Use this with ITGC, vendors and monitoring next

ITGC Internal Audit Checklist

Use ITGC testing for access, change, backup, jobs, interfaces and audit logs.

AI-Enabled Fraud Checklist

Extend cyber tests to phishing, fabricated documents, deepfake approvals and synthetic identity risk.

Third-Party Outsourcing Risk Guide

Review vendor criticality, cyber/data access, SLA, sub-outsourcing and exit readiness.

Data Governance & Master Data Controls

Connect cyber risk with data ownership, critical data elements, retention and monitoring handoff.

Continuous Monitoring Rules

Turn cyber signals into recurring exception rules with owner review and false-positive handling.

Risk Acceptance & Escalation Register

Track accepted cyber risk with authority, expiry, compensating controls and committee visibility.

FAQ

Common questions answers

What should an internal audit cybersecurity checklist cover?

A cybersecurity internal audit checklist should cover ransomware readiness, identity and privileged access, incident response, vulnerability and patch management, logging, cloud/SaaS configuration, third-party access, privacy breach evidence and continuous monitoring signals.

Is cybersecurity internal audit the same as ITGC testing?

No. ITGC testing focuses on access, change, operations and report reliability. Cybersecurity internal audit is broader: threat readiness, incident response, recovery, vulnerability exposure, cloud posture, vendor cyber access and privacy/data-breach handling.

Can internal audit conclude whether a cyber incident is reportable under CERT-In or DPDP?

Internal audit can check whether management assessed reporting obligations, retained evidence and followed the incident workflow. Legal/regulatory reporting conclusions should remain with management, legal, DPO/security leadership and sector specialists as applicable.

Which cyber controls can be monitored continuously?

Common monitoring candidates include privileged access changes, leaver access, high-severity alerts, failed backups, overdue restoration tests, critical vulnerabilities past SLA, public cloud storage, stale API keys, vendor access and unusual personal-data exports.