![]() |
|
#1
|
|||
|
|||
|
Any of you QSA folks out there can tell me where can I get an audit procedure with "high" "medium" "low" risk ratings? On our last (also the first) audit we got from our QSA Auditor the non compliances with these ratings. We're not working with this QSA
any longer, and I'd like to get the source of where he got this ratings from. ![]() In a few months we'll have to do another ROC, plus another audit for another subsidiary. For this other one, we've done an internal self assessment. I need to prioritize our ramp up/remediation plans to get ready for these audits. I have no idea where the previous QSA got the ratings for each section of the audit procedure from. I only have the rated gaps, and it's based on the 1.0 version. Any ideas? We haven't selected the new QSA yet .
|
|
#2
|
|||
|
|||
|
To be honest, I suspect any such ratings were probably made up according to your site/environment and hopefully included an assessment of the bang for buck out of fixing various issues/gaps, and ease of implementation/resolution etc.
Lyal |
|
#3
|
||||
|
||||
|
For our PCI compliance assessments, we have two "ratings" we issue for findings.
For these two ratings, we use a high, medium and low ranking. We define these rankings as follows.
For our PCI assessments, any issues related to PCI DSS compliance are to be rated with a Relative Risk level of 'High'. I hope this helps you to understand what your QSA might have been trying to tell you.
__________________
Jeff Hall, Director, Risk Advisory Services RSM McGladrey Inc 801 Nicollet Mall, 11th Floor, West Tower Minneapolis, MN 55402-2526 612 376 9280 - office 612 395 7280 - facsimile www.mcgladrey.com The views presented are those of the writer and are not necessarily those of RSM McGladrey Inc |
|
#4
|
|||
|
|||
|
Thanks folks, this helps. We do have an internal rating system.
Cheers
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|