Internal Auditing

Outsourced Information Security Internal Auditing

certificate icon

100% Certification Success Rate

companies icon

100+ Companies Served

experience icon

15+ Years of Experience

    Are you seeking a reliable and professional partner to help address your internal audit needs? Look no further! We offer top-notch information security internal audit services that can help you save time and money while ensuring compliance with key industry standards like ISO 27001, SOC 2, & CMMC.

    Our experienced auditors will work closely with you to understand your business and tailor our services to meet your needs. We deliver our services on a state-of-the-art GRC platform to ensure a consistent audit experience and accurate assessments of your cybersecurity practices.

    Together we will ensure that you are provably secure & compliant.

    Are you seeking a reliable and professional partner to help address your internal audit needs? Look no further! We offer top-notch information security internal audit services that can help you save time and money while ensuring compliance with key industry standards like ISO 27001, SOC 2, & CMMC.

    Our experienced auditors will work closely with you to understand your business and tailor our services to meet your needs. We deliver our services on a state-of-the-art GRC platform to ensure a consistent audit experience and accurate assessments of your cybersecurity practices.

    Together we will ensure that you are provably secure & compliant.

    What types of internal audits does PPS conduct?

    As PPS’s client base generally needs to be “provably secure and compliant,” we most frequently audit/assess our clients against third party attestable frameworks like ISO 27001, SOC 2, and CMMC. Over our 22+ year history, we have assessed our clients against dozens of frameworks including:

    • ISO 27701
    • HIPAA
    • PCI DSS
    • NIST CSF
    • ISO 27002
    • TISAX
    • MPAA
    • NYS DFS 500
    • GDPR
    • CCPA
    • NIST 800-53
    • CIS CSC

    We have a flexible, proven process to conduct your Internal Audit and help you throughout the year to efficiently operate, continuously improve, and validate the effectiveness of your program, culminating in a successful Surveillance Audit. Where privacy or information security Non-Conformities (NV) or Opportunities for Improvement (OFI) gaps are identified, PPS has the expertise necessary to help you drive them to closure.

    Do you conduct ISO 27001 ISMS Internal Audits?

    Absolutely, to the tune of 100+ ISO 27001 ISMS Internal Audits per year!

    We have a flexible, proven process to conduct your Internal Audit and help you throughout the year to efficiently operate, continuously improve, and validate the effectiveness of your program, culminating in a successful Surveillance Audit. Where privacy or information security Non-Conformities (NV) on internal audit page or Opportunities for Improvement (OFI) gaps are identified, PPS has the expertise necessary to help you drive them to closure.

    How do you ``scope`` an ISO 27001 Internal Audit?

    Several dimensions significantly influence the audit program:

    • The number of geographic locations in the scope
    • Whether you do a complete ISMS Audit or one aligned with the registrars’ audit program (most relevant in surveillance years)
    • Whether additional ISO standards are in scope (e.g., 27701, 27017, 27018)
    • Whether you want to leverage the Internal Audit to validate compliance with another framework (e.g., HIPAA, CMMC, TISAX, CSA Stars)

    We will work with you during the pre-sales process to optimally scope your ISMS Internal Audit to meet your specific needs.

    What is an ISO 27001 ISMS Internal Audit?

    An ISO 27001 internal audit reviews an organization’s Information Security Management System (ISMS) to validate that the ISMS meets the standard’s requirements and the organization’s objectives and policies. It identifies gaps or deficiencies in the ISMS (e.g., Non-Conformities, Opportunities for Improvement) to minimize information security risk and promote continuous improvement.

    An annual ISO 27001 ISMS Internal Audit is required to maintain ISO 27001 Certification.

    What is a SOC 2 Readiness Assessment?

    A SOC 2 Type 2 readiness assessment is a sampled audit of your cybersecurity program that determines your level of preparation for the formal SOC 2 audit. The assessment will allow your team to resolve any issues or gaps identified and maximizes the likelihood of you receiving a “clean” SOC 2 report. It is an excellent tool for service organizations that don’t want to undertake the potentially substantial cost of a SOC 2 audit without a high degree of confidence that they satisfy one or more of the trust services criteria (e.g., security, availability, processing integrity, confidentiality, and privacy.)

    Is there a difference between an Information Security Internal Audit and a Gap Assessment?

    Both are a mechanism to assess whether controls conform with requirements but have subtleties in the approach and their best use.

    • An InfoSec Gap Assessment is a determination of the degree of conformance of your organization to the requirements of a specification or standard (e.g., ISO 27002 or CCP). It is generally a “lighter touch” review (e.g., more design-centric, less evidence collected). Gap Assessments often occur at the beginning of the journey to comply with a standard to determine what “gaps” need to be addressed.
    • An InfoSec Internal Audit is a determination of the degree of conformance of your organization to the requirements of a specification or standard (e.g., ISO 27002 or CCP) or your own defined cybersecurity program. It is generally a “heavier touch” review (e.g., design and operation-centric, more evidence collected). Internal Audits are a more formal approach to validate the conformance, usually of a regulated or third party attested cybersecurity program.

    What is a Control Maturity Assessment?

    Control maturity is a more comprehensive and effective way of assessing and reporting conformance with an information security standard during a Gap Assessment. For example,

    Standard Assessment & Reporting Approach CMA Assessment & Reporting Approach
    Not Applicable Level 1: Initial – ad-hoc and unknown
    Non Compliant Level 2: Managed – managed on the project level
    Partially Compliant Level 3: Defined – proactive rather than reactive
    Fully Compliant Level 4: Quantified – measured and controlled
    Level 5: Optimized – stable and flexible

    Control Maturity Assessments provide a more thorough and nuanced way to assess control conformity and establish control maturity targets (e.g., Our goal is to improve our Business Continuity maturity from 1.5 to 3 over the next year).

    Contact Us Today

    Have a question? Please fill out the form and we will reply as soon as possible.

    Featured Resources

    CBIZ General Light v

    What is the ISO 27001 Climate Change Amendment and How Could It Impact Your Business?

    Read More
    CBIZ General Green v

    Federated vs. Centralized vs. Hybrid Governance for Citizen Development—Which is Right for My Business?

    Read More
    CBIZ General Light v

    Third-Party Risk and Shadow AI in Citizen Development—What Do CISOs Need to Know?

    Read More
    CBIZ General Light v ()

    Managing AI Risk in Citizen Development: Key Strategies for CISOs

    Read More
    CBIZ General Green v

    CMMC Level 2 Compliance—What Should We Do Now as a DIB Org with CUI?

    Read More
    Virtual CISO Services: What's Included?

    CMMC Phase 2 Suspended: What Defense Contractors Need to Do

    Read More
    How to Choose an AI Governance Framework (ISO 42001 vs. NIST)

    How to Choose an AI Governance Framework (ISO 42001 vs. NIST)

    Read More
    CBIZ General Light v

    Virtual CISO Services: What’s Included?

    Read More
    CBIZ General Light v

    AI Governance Compliance: Regulations You Need to Know

    Read More
    CBIZ General Green v

    The CMMC Phase 2 Pause: What’s Most Important and What to Do Next

    Read More
    CBIZ General Light v

    The CMMC Assessment Pause Took Away Your Witness

    Read More
    CBIZ General Light v

    CMMC Pause—Will It Reduce DIB Cyber Compliance Costs?

    Read More
    Episode Graphic

    Episode 161: The Future of Citizen Development: Risks, Rewards, and Best Practices with ChatGPT

    Listen Now
    Untitled design

    Episode 160: Managing Identity in the Age of AI Agents With Geoffrey Mattson

    Listen Now
    Episode Graphic

    Episode 159: The New Security Stack: Doors, Data, and AI With Jeffrey Friedman

    Listen Now
    Episode Graphic ()

    Episode 158: AI Is Increasing Your Cyber Risk – Can It Also Reduce It? With Mike Armistead

    Listen Now
    Untitled design

    Episode 157: AI Security: Testing, Exploits, and Threat Feeds With Marco Figueroa

    Listen Now
    Untitled design T

    Episode 156: AI Security: Threat Modeling & Pipeline Evolution with Jason Rebholz

    Listen Now
    Untitled design T

    Episode 155: Incident Response Testing in Cloud Forward Organizations with Matt Lea

    Listen Now
    Untitled design T

    Episode 154: How DORA Will Impact US Companies with Dejan Kosutic

    Listen Now
    Untitled design T

    Episode 153: Inside ISO 42001: The Future of AI Governance

    Listen Now
    Untitled design T

    Episode 152: Granular, Persistent, Zero Trust: The Case for File-Level Security

    Listen Now
    Trust, But Verify: How HITRUST is Reshaping Assurance

    Episode 151: Trust, But Verify: How HITRUST is Reshaping Assurance

    Listen Now
    Episode Graphic

    Episode 150: Is OSCAL the Future of Security Documentation

    Listen Now
    overcoming ai risk

    Overcoming AI Risk: Essential Strategies for
    Understanding and Managing AI Challenges

    Watch Now
    CD PPS Webinar Updated () ()

    The Evolving Threat Landscape:
    Understanding Modern Cybersecurity Risk

    Watch Now