This component allows an auditor and host to come to an understanding of the level of access that an auditor will have, what is off limits, and the process for modifying the scope of the audit when new information arises. 13,14 This component consists of a process where the auditor collaboratively creates an assessment plan with key members of the organization. A core tenet of SAFETAG is building agency in organizations to improve their digital security. To that end, collaboratively creating an assessment plan with the organization helps to clarify not only the audit scope - from discussing what sensitive data may be exposed to what systems may be disrupted in the process of the audit - but it also helps reveal the ability of the organization to support and respond to the audit findings. Overview Determine a point person for the audit and exchange contact information.15 Explain and get approval to the scope of audit from the host.16,17 Agree to the time-line, location, and attendees of the on-site audit.18 Codify data security standards for audit communication and evidence handling.19 If funded externally, identify what should be reported to external funder.20 Materials Needed Considerations In addition to the overall mandate to send information encrypted to the organization, also demand encrypted communication back from them. Failure to establish a secure planning channel also contributes towards a no-go situation by putting both the auditor and organization at risk. Walkthrough An agreement signed by both parties outlining the scope of the audit including: The start and end dates of the audit. The location where the on-site audit will take place.21 The responsibilities of the host staff. The responsibilities of the auditor. The host names and IP ranges of any services run by the organization.22 Emergency contact information for the organization. 23 Page 16 of 240

Select target paragraph3