For internal audit teams
who give independent assurance over cyber controls
Internal audit functions inside large organisations run independent walkthroughs over IT general controls, application controls, vulnerability management operation, identity and access reviews, change management, and incident response readiness. SecPortal gives the third line of defence one workspace for control testing, finding ownership, evidence capture, management response tracking, and the reporting that goes to the audit committee.
No credit card required. Free plan available forever.
A cybersecurity audit platform built around the live engagement record
Internal audit functions inside large organisations provide independent assurance over IT general controls, application controls, vulnerability management operation, identity and access reviews, change management, incident response readiness, third-party risk, and cloud security posture. The work runs on a separate cycle from the operational security programme and against a stricter independence standard. Most internal audit teams run cyber engagements through a generic audit management platform, a SOX-focused IT general controls tool, or a spreadsheet stack the second line keeps in parallel, and pay the cost in working-paper reconciliation hours and in audit committee briefings that no longer match what the operations team is reading on the same day.
SecPortal gives the third line of defence one workspace for control walkthroughs, observation capture with CVSS scoring, evidence management, management response tracking, exception decisions, and audit committee reporting. The audit engagement opens on the same platform the operations team runs on, but the engagement record stays independent. Findings carry the evidence chain, the activity log captures the change-event reconciliation across the observation period, role-based access keeps the segregation between assurance and operations at the platform level, and the audit committee reads a report that regenerates from the same record the auditees work against.
Internal audit capabilities in one workspace
Independent engagement records
Open a cyber audit engagement on the workspace separate from the operational engagements the second line runs. Findings, control mappings, evidence, and conclusions live on the audit engagement record while operational status remains observable on the operations records, so independence holds at the platform level rather than the spreadsheet level.
Reproducible evidence on the live record
Each observation carries the CVSS vector, severity, evidence document, mapped control, owner, and remediation status on one record. Working papers reconcile against the live engagement record rather than a static snapshot, so evidence currency is observable on the same view the audit committee reads.
Activity log for the observation period
Every state change on every finding, control, exception, remediation step, retest, and report record is timestamped by user. CSV export of the activity record covers the change-event reconciliation auditors read across the observation period, so the test of operating effectiveness reads from the live trail rather than a multi-team reconstruction.
Exception decisions with the full chain
Risk acceptances and compensating controls captured during fieldwork attach to the finding record with the linked finding, severity, compensating controls, residual likelihood, residual impact, business rationale, expiry, and review cadence. The eight-field decision chain holds across audit rotation, audit committee turnover, and the next cycle.
Multi-framework control mapping
Pre-built control templates cover ISO 27001 Annex A, SOC 2 Trust Services Criteria, Cyber Essentials, PCI DSS, and NIST control mappings. A single observation can map to multiple frameworks, so the IT general control test set under SOX, the ISO 27001 surveillance audit, and the SOC 2 Type 2 examination read the same underlying finding evidence.
AI-assisted audit reporting
Generate the executive summary, the technical writeup, the remediation roadmap, the audit committee deck, and the management response readout from the same engagement data the operational programme runs on. The chief audit executive edits a draft rather than writes from blank, and the audit narrative regenerates against the same record between cycles rather than drifting in working papers.
How internal audit teams run the cyber audit inside SecPortal
The audit cycles that hold against questions read from a small set of disciplines. SecPortal supports each one rather than a single phase of the audit calendar.
- Plan the annual cyber audit calendar against the engagement workspace so each ITGC, application control, vulnerability management programme review, identity and access review, change management review, incident response readiness review, third-party risk review, and cloud security review opens as an engagement with its own record.
- Sample IT general controls (access provisioning, access deprovisioning, privileged account review, MFA enforcement, password policy enforcement, change approval, segregation of duties between developer and production, backup verification, restore verification, vendor access review, terminated user deactivation) across the observation period using finding templates the team picks once and reuses every cycle.
- Pair observation evidence to the underlying control owner record. Engineering reads the same finding the audit team reads, the named owner attaches remediation status to the same record, and the next audit cycle reads the chain back without a working-paper reconstruction.
- Track management response and corrective action plan commitments against severity-driven SLA windows. Aged observations surface alongside cadence completion so the remediation-gap axis and the cadence axis read together on the audit committee dashboard.
- Reconcile the change-event record (asset, scope, control, remediation, people axes) for the observation period from the activity log rather than from chat history and email threads, with CSV export when the audit working papers need the trail in their own format.
- Use role-based access control to grant viewer privileges to internal audit observers across operational engagements while assurance findings stay on a separate engagement record. MFA is enforced on every account and document upload preserves the evidence chain.
From scoping the audit engagement to the audit committee readout
The audit engagement opens with the framework, the in-scope control set, the engagement team, and the observation period on the engagement record, then runs through to the audit committee readout on the same record.
- 1Open the cyber audit engagement on the workspace and load the relevant ITGC, application control, programme review, or technology domain control set. The control templates populate the engagement record with the test condition, the evidence requirement, the sampling guidance, and the conclusion field ready to capture working-paper output.
- 2Walk the in-scope controls with the technical owners. Mark each as effective, partially effective, ineffective, or not applicable on the engagement record. Attach sampled evidence (configuration export, access review export, ticket evidence, scanner output) via document upload or CSV import with custom column mapping so the working paper points to the artefact rather than a screenshot pasted into a Word document.
- 3Capture observations as findings with CVSS scoring. Each observation gets a severity, a named owner, an SLA window driven by severity, mapped controls, and remediation guidance from the 300+ template library. The observation, the affected control, and the management response live on one record from the day the observation is raised.
- 4Track management response and the corrective action plan as remediation status against the observation record. Retesting workflows pair the verification evidence (rescan output, configuration check, document update) to the original observation rather than opening a parallel finding, so the closure trail is reconstructable later.
- 5Capture deferrals and risk acceptances on the same engagement record using the eight-field exception decision chain (linked finding, severity, compensating controls, residual likelihood, residual impact, business rationale, expiry, review cadence). The audit committee reads a structured exception register rather than a narrative paragraph.
- 6Generate the audit committee readout, the chief audit executive briefing, the management response readout, and the next-cycle planning input from the live engagement record. The deck regenerates from the same data the operational team runs on, so the audit narrative and the operational picture reconcile against one record.
Where to start
Most internal audit functions adopt the platform in three phases: bring the cyber audit engagements onto the same workspace the operational security programme already runs on so observations and operational findings sit on one record, layer in the management response tracker and the exception register so corrective action plans and deferrals stop hiding in audit project plans, then consolidate the audit committee reporting onto the same record so the narrative reconciles against operational reality between cycles. The relevant workflow, feature, and framework pages explain each phase in detail.
- The walkthrough discipline, the control narrative artefacts, and the test condition recording sit on the audit walkthrough and control narrative evidence workflow, with the fulfilment side covered on the audit fieldwork evidence request fulfilment workflow, and the periodic second-line pack the third line scopes against on the security finding evidence pack handoff to internal audit workflow.
- Findings management with CVSS scoring sits on the findings management feature page, the compliance and control mapping on the compliance tracking feature page, and the audit trail on the activity log feature page.
- The audit support cycle from kickoff to issued report sits on the compliance audits use case, the closure cycle between assessments on the control gap remediation workflow, and the retention and disposal trail on the audit evidence retention and disposal workflow.
- The exception register that captures management deferrals and risk acceptances lives on the vulnerability acceptance and exception management use case, with a copy-ready org-wide ledger artefact in the security exception register template and the running tracker artefact in the audit evidence tracker.
- Framework-specific control mappings live on the ISO 27001 framework page, the SOC 2 framework page, the NIST SP 800-53 framework page, and the CIS Controls framework page.
- The deeper analysis of why working-paper evidence ages between audits and how to keep the currency reproducible across the observation period sits on the audit evidence half-life research, and the cross-framework reuse view on the multi-framework control crosswalk economics research.
SecPortal is built for internal audit functions that want one platform for the full audit engagement: independent observation capture, evidence on the live record, management response tracking, exception decisions, retest verification, and audit committee reporting. The chief audit executive gets a faster read, the audit committee gets a deck that holds against questions, and engineering reads the same observation the audit team reads, so the next cycle starts from a clean continuity record rather than a working-paper rebuild.
If your function sits inside the second line of defence rather than the third, the sister page SecPortal for GRC and compliance teams covers how the same workspace supports findings management, exception tracking, and evidence on the operational side.
If the audit committee reads the cyber audit alongside the wider security programme view, the SecPortal for CISOs and security leaders page covers the leadership read that regenerates from the same record internal audit observes.
If audit fieldwork covers internal security operations as well as IT general controls, the SecPortal for internal security teams page covers the operational side of the engagement record the audit team observes against.
If your evaluation is against a continuous compliance automation platform that automates SOC 2 and ISO 27001 evidence collection across cloud, identity, HR, and code surfaces, the SecPortal vs Vanta comparison, the SecPortal vs Drata comparison, and the SecPortal vs Hyperproof comparison walk through where automated compliance evidence stops and where the security testing engagement record picks up.
The problems you face
And how SecPortal solves each one.
Cyber audit walkthroughs run against control evidence held in operations team spreadsheets and shared drives. Currency between the operational view and the audit view drifts the moment the operations team updates a record, and the internal audit team has no independent activity trail to reconcile against
Open the cyber audit engagement on the workspace. Findings, control mappings, exceptions, remediation status, and retests live on the same engagement record the operational programme reads. The activity log captures every state change by user and timestamp with CSV export, so the change-event reconciliation across the observation period reads from the live record rather than from a multi-team excavation across email and chat.
Test of design and test of operating effectiveness require evidence sampled across an observation period. Without a unified record, sampling decisions, evidence pulls, and judgement calls live in working papers nobody on the engineering side of the wall can reproduce later
Findings management captures the test, the sample reference, the CVSS-scored observation, the evidence document, and the owner on one record. Document upload attaches sampled artefacts to the engagement and version control keeps the trail intact. The sampling rationale, the population definition, the test condition, and the conclusion stay on the same record the audit committee reads on review.
The link between an observation written into the audit report and the underlying technical finding is rebuilt by hand for every readout. Engineering reads one record, internal audit reads another, and the audit committee reads a narrative neither side can defend against a question
Observations are findings on the engagement record. Each carries the CVSS vector, severity, evidence, owner, mapped control, and remediation status. The audit report regenerates from the same engagement data the operational programme runs on, so the audit committee narrative and the operational picture reconcile against one record rather than three.
Management response and corrective action plans get captured in audit project plans, then live in separate trackers across operations, with no observable link between the agreed action, the underlying control owner, and the remediation evidence
Corrective action commitments attach to the finding as remediation status. The agreed action, the named owner, the SLA window driven by severity, and the verification approach sit on the finding record. Retesting workflows pair the verification evidence to the original finding rather than opening a new record, so closure of an observation reads from one record and the chain is reconstructable later.
Risk acceptances, compensating controls, and management deferrals captured during audit fieldwork sit in narrative paragraphs that the next audit cycle and the audit committee cannot reconstruct as defensible decisions
Exception capture runs on the same engagement record as the finding. The linked finding, severity, compensating controls, residual likelihood, residual impact, business rationale, expiry, and review cadence form a structured decision chain. The next internal audit cycle, the external auditor, and the audit committee read the same record, so exceptions remain defensible across rotation rather than dissolving into narrative.
Quarterly and annual reporting to the audit committee, the chief audit executive, and the audit committee chair gets rebuilt from screenshots, snapshots of last quarter spreadsheets, and copy-paste from prior decks. The board narrative drifts from the operational picture between cycles
AI-generated reports produce executive summaries, technical writeups, remediation roadmaps, and audit-readiness summaries from the live engagement record. The chief audit executive reads a draft regenerated from the same data the operational team works against, edits rather than rewrites, and the audit committee deck holds against questions because it is the same record the auditees operate on.
Independence requirements mean the audit team needs read access to operational records without the ability to change finding status, remediation evidence, or exception decisions. Granting full platform access compromises segregation of duties; granting no access forces a paper review cycle
Role-based access control supports viewer roles that observe the engagement, finding, exception, and activity log records without write privileges. Multi-factor authentication is enforced on every account. Internal audit observes the live record, captures independent observations on a separate engagement, and the segregation between assurance and operations holds at the platform level rather than at the spreadsheet level.
IT general control testing covers many narrow techniques (change management approval evidence, access review evidence, privileged account review evidence, password policy enforcement evidence, MFA enforcement evidence, terminated user deactivation evidence, vendor access review evidence, backup test evidence). Building working papers across all of them inside a generic GRC platform takes weeks and the trail still has to be reconciled against operations records
Open a control walkthrough engagement on the workspace. Each ITGC test sits as a finding template (300+ templates ship out of the box) with the test condition, the evidence requirement, and the conclusion field on the record. Operations evidence attaches via document upload, the technical configuration check attaches via scanner output (Nessus or any CSV with custom column mapping), and the walkthrough closes on the same record the audit report reads from.
Key features for you
Vulnerability management software that tracks every finding
Compliance tracking without a full GRC platform
Every action recorded across the workspace
Orchestrate every security engagement from start to finish
Document management for every security engagement
Multi-factor authentication on every workspace
AI-powered reports in seconds, not days
Collaborate across your entire team
Run the cyber audit on the same engagement record operations work against
Independent control walkthroughs, reproducible evidence, management response tracking, exception decisions, and audit committee reporting on one versioned workspace. Free plan available.
No credit card required. Free plan available forever.