Security costs to rise this year

Updated newsguy 0 Tallied Votes 763 Views Share

According to the latest market research coming out of security vendor nCircle the cost of security auditing is heading in one direction, and that's upwards. Some 47 percent of IT security professionals to the nCircle survey expect that security auditing costs will increase during 2010 while only a very optimistic 8 percent see them falling. Interestingly, a huge 83 percent of them reported that they are effectively identifying security and compliance issues prior to any audit, which is certainly good news.

"The increasing complexity of regulatory requirements continues to be a key cost driver for many companies’ compliance initiatives" says Elizabeth Ireland, Vice President of Strategy for nCircle, who continues by adding "It's interesting to note that, while a significant percentage of companies believe they are identifying security and compliance issues prior to beginning an audit, organisations are not yet realising the cost savings that can come from process maturity. Unless companies have a strategy that automates the continuous monitoring required for various regulations and can report on it to suit the requirements of a specific audit, the process remains very resource intensive and costly".

Dani AI

Generated

Good point, . Rising audit costs are usually a process problem more than a price problem: manual evidence collection, unclear control ownership, and broad, unfocused scopes drive hours (and invoices). The practical response is to make audits an outcome of day-to-day operations, not a separate project that consumes large teams at the last minute.

  • Narrow scope and prioritize. Limit audited assets to what truly matters and focus on the highest-risk controls first.
  • Build an evidence locker. Centralize timestamps, signed configuration snapshots, and reports so evidence is one-click away.
  • Automate repeatable evidence. Schedule scans, exports and reports; push them into the locker with a consistent file naming and retention policy.
  • Map controls to artifacts. Maintain a simple control-to-evidence matrix so auditors are shown exactly what proves each control.
  • Run pre-audit dry runs. A short internal checklist run finds missing items early and cuts surprise follow-ups.
  • Consolidate tooling and owners. Fewer tools and a named control owner reduce coordination overhead during audits.
  • Negotiate audit approach. Ask for remote evidence acceptance, clear sampling rules, and an agreed-upon format for deliverables.

Implementation notes: start with two controls that currently take the most auditor time and automate those first. Keep human-readable narratives alongside machine outputs so an auditor can see intent and context. Preserve provenance: timestamping, hashing, and simple versioning make evidence and its history defensible. Expect upfront effort; the payoff is fewer auditor hours, less firefighting, and a more repeatable, lower-cost compliance cycle.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.