How to Create a 30-60-90 Day Plan for Environment Audits?

0
6
Asked By TechWhiz42 On

I'm looking for advice on creating a solid 30-60-90 day plan focused on auditing an environment. Any tips on how to build one or examples would be great! I'm especially interested in identifying gaps or issues effectively and would appreciate any frameworks or resources that could guide me through this process.

4 Answers

Answered By CuriousTechie On

Just curious, why does IT get tied into performance plans for new hires?

Answered By TechWhiz42 On
Answered By AuditGuru99 On

When setting up a plan for an audit, consider the criticality of findings. For instance, prioritize high-severity vulnerabilities to be resolved within a month, medium ones in 1-2 months, and so on. If you're new to this, starting with a Security+ certification could be helpful, and aiming for a CISSP is a good bonus. Don't forget about NIST standards and the NISPOM for solid resources, especially if you're in the U.S!

Answered By OrderlyAdmin24 On

If you're embarking on an audit, first assess how chaotic the environment is—it's common for new admins to inherit messy setups without proper documentation. I recommend gathering insights from community experiences to create a list of necessary tasks. Start with a baseline framework, such as the CIS, and gradually work towards STIG compliance. As you conduct your audit, rank the controls by their importance to your business—high, medium, or low. Let these findings shape your 30-60-90 day plan!

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.