SANS 20 Critical Controls Review

1 post / 0 new
millerd

During our last NCUA exam, I was told that Audit should be creating and maintaining a SANS 20 Critical Controls document of the IT Department.  Has anyone else been given the same directive?  If so, do you have a framework/template to document and report the results?ThanksDeanne MillerVP Audit ServicesMembers 1st FCU