Knowledge base — IT compliance audits (NIS2, DORA, GDPR, ISO 27001)
Practical guides to IT security and regulatory compliance audits — written by audit practitioners at Virtline.
NIS2 audit — who is covered, what the obligations are, and how to prepare
NIS2 audit: who falls under the directive, what obligations it imposes, how to run a gap analysis and prepare a board-ready compliance report.
Read →Which tools support NIS2, DORA and banking compliance audits? Selection criteria
How to choose a tool for NIS2, DORA and banking IT compliance audits: criteria for banks and regulated organizations, questions to ask vendors, common risks.
Read →DORA audit — ICT requirements, third-party risk and how to prepare
DORA audit (EU 2022/2554): the regulation’s pillars, ICT risk management, the register of information, resilience testing and how to prepare a report.
Read →GDPR audit — security of processing (Art. 32), DPIA, RoPA and the 72-hour breach
GDPR audit (EU 2016/679): security of processing (Art. 32), DPIAs, records of processing (RoPA), the 72-hour breach notification and how to prepare.
Read →Offline (on-premise) compliance audit — keeping full data control
Offline/on-premise compliance audits: why banks keep data in-house, when it is needed, the benefits, and how Bank Mode in Audnexa keeps data on site.
Read →