Skip to main content

Internal Cybersecurity Audit

An internal assessment that reviewed security controls, documented gaps, and produced a prioritized remediation roadmap.

Organization
Cybersecurity Internship Portfolio
Duration
3 weeks
Project Type
Internal Audit
NIST CSFCIS ControlsISO 27001

Objective

Conduct a comprehensive cybersecurity assessment using ISO/IEC 27001, CIS Controls v8.1, and NIST CSF 2.0 to identify security gaps and provide actionable recommendations.

NIST CSFCIS ControlsISO 27001

Step-by-Step Execution

  1. Step 1

    Assessment Scoping

    • Defined systems in scope, including HR database, payment platform, and email servers.
    • Clarified critical business processes and assessment boundaries.
  2. Step 2

    Framework Selection & Mapping

    • Reviewed ISO 27001 Annex A, CIS Controls v8.1, and NIST CSF 2.0.
    • Created a unified control mapping to eliminate redundancy.
  3. Step 3

    Evidence Gathering

    • Collected policies, procedures, network diagrams, interview responses, firewall configurations, vulnerability scan reports, and screenshots of technical configurations.
  4. Step 4

    Control Testing

    • Validated implementation and effectiveness.
    • Reviewed examples such as password complexity settings against CIS benchmarks and log retention against ISO 27001 requirements.
  5. Step 5

    Gap Identification

    • Identified gaps such as ADDI lacking formal log monitoring and Diaspocare backups failing to meet RPO objectives.
  6. Step 6

    Risk Ranking

    • Assigned Critical, High, Medium, and Low ratings.
    • Prioritized risks according to business impact, likelihood, and compliance consequences.
  7. Step 7

    Remediation Planning

    • Created detailed remediation plans with required action, responsible owner, and timeline.
    • Example recommendation: implement centralized log management within 90 days.
  8. Step 8

    Reporting

    • Produced an Internal Audit Report containing executive summary, technical appendix, business-focused recommendations, and compliance mapping.

Deliverables

Audit

Internal Audit Report

Structured report with scope, findings, risk ratings, and remediation recommendations.

Supports management decisions and future control improvement planning.

Risk Treatment

Remediation Roadmap

Prioritized list of corrective actions with owners, timelines, and expected outcomes.

Turns assessment findings into practical next steps.

Skills & Insights Gained

Audit methodologyEvidence collectionFramework implementationTechnical analysisExecutive reportingProfessional documentationRisk communication

Continue exploring

Governance

Governance Policy Development

A structured policy development engagement aligning security expectations with business objectives and recognized frameworks.

ISO 27001NIST CSFCIS Controls
View case study

Risk Management

Enterprise Risk Assessment

A risk assessment project documenting assets, threats, likelihood, impact, and treatment options for management review.

CIS RAMNIST CSFISO 27001
View case study

Vendor Risk

Third-Party Risk Assessment

A vendor review workflow covering due diligence, control questions, risk scoring, and onboarding recommendations.

NIST CSFISO 27001CIS Controls
View case study