PREPARATION
SUMMARY
This component consists of trip preparation activities that are needed to ensure the
technical and facilitated components of the audit are able to be conducted effectively and
within the on-site time-frame and in coordination with the organization.
PURPOSE
A SAFETAG audit has a short time frame. Preparation is vital to ensure that time on the
ground is not spent negotiating over the audit scope, updating the auditors systems,
searching for missing hardware, or refreshing oneself with the SAFETAG framework. To
that end negotiations with the host organization help reveal if the organization has the
capacity to undertake the audit and respond to its findings.
GUIDING QUESTIONS
Does the organization have existing digital security practice or attempted to
implement them in the past?
What is the process for procedure for incident handling in the event that auditor
cause or uncover an incident during the course of the assessment?
What are the legal, physical, or social risks for the auditor & organization associated
with conducting the audit or having audit results leak? 2
Does the security situation of the location or organization require additional
planning? Are your software tools up to date and working as expected?
THE FLOW OF INFORMATION
Information
Threats
Actors
Results
Activity
Threats
Actors
Capacity
Capacity
Barriers
Barriers
Activities
Activities
Vulnerabilities
Vulnerabilities
Assets
Assets
Preparation Information Flow
APPROACHES
Create an Assessment Plan: Have a "scoping" meeting that outlines the level of
access that an auditor will have, what is off limits, and the process for modifying the
scope of the audit when new information arises. 3,4
Negotiate a Confidentiality Agreement: Negotiate an agreement with the
organization that outlines how an auditor will protect the privacy of the organization
and the outcomes of the audit.
Establish an Emergency Contact: Establish a procedure for incident handling and an
Page 13 of 240