Notes (alphabetical)
Search to quickly find notes, articles, guides, and resources across the site.
Search to quickly find notes, articles, guides, and resources across the site.
Prudential Standard 234 Information Security
Source [Prudential Standard 234 Operational Risk Management (PDF)](https://www.apra.gov.au/sites/default/files/2023-07/Prudential%20Standard%20CPS%20230%20Operational%20Risk%20Management%20-%20clean.pdf
Attack Surface Management (ASM) is the continuous process of identifying, monitoring, and reducing an organisation’s external and internal attack surfaces to minimise cybersecurity risk. ASM involves discovering and assessing all digital assets, including known and unknown internet-facing systems, cloud environments, third-party dependencies, and shadow IT. Attack Surface Management benefits from advances in AI and machine learning and is being used increasingly by organisations as part of their third party risk management strategy. ...
Further reading What Is Attestation? Definition, How It Works, History, and Example - Investopedia Attestation, in Confidential Computing - Microsoft Learn Attestation vs direct reporting - ICAEW
The audit universe is the comprehensive list of all the potential audit areas within an organisation. It serves as a foundational tool for planning and prioritising internal audit activities. Components within the Audit universe may be called Auditable areas, units or entities, depending on the lens the auditor is taking. Further reading Developing a Risk-based Internal Audit Plan - IIA Practice Guide Related pages Risk universe