Audit Approach
As an element of the University’s core business functions (payroll, financials, student, and medical), Physical Security of IT Resources will be audited every three years using. The minimum requirements set forth in the General Overview and Risk Assessment section, below, must be completed for the audit to qualify for core audit coverage. Following completion of the general overview and risk assessment, the auditor will use professional judgment to select specific areas for additional focus and audit testing. Specifically the minimum scope of the risk assessment and audit will include the following as they relate to the Campus Data Center:
• Environmental Controls
• Natural Disaster Controls
• Supporting Utilities Controls
• Physical Protection and Access Controls
• System Reliability
• Physical Security Awareness and Training
• Contingency Plans