An information security audit is all about defining how to use technology processes to protect valuable assets like patents, knowledge, customer lists, employee records, strategic planning and reporting.

Information Security is the practice of defending information from unauthorized access, use, disclosure, disruption, modification, perusal, inspection, recording or destruction.

An information security audit is an audit on the level of information security in an organization. Within the broad scope of auditing information security, there are multiple types of audits, multiple objectives for different audits, etc. Most commonly the controls being audited can be categorized as technical, physical and administrative. Auditing information security covers topics from auditing the physical security of data centers to auditing the logical security of databases, and highlights key components to look for and different methods for auditing these areas.

