Prior to commencing the audit at agencies we reviewed their policies and procedures for identifying and responding to cyber threats. This included reviewing information security policies, incident response plans, staff induction processes, and security awareness training.