CAQ helps boards manage cybersecurity risk

The Center for Audit Quality has released a tool to help members of the boards of public companies oversee cybersecurity risk management in their organization.

The publication, Cybersecurity Risk Management Oversight: A Tool for Board Members, offers questions that board members can use as they discuss cybersecurity risks and disclosures with management and CPA firms. The questions are categorized into four main groups: understanding how the financial statement auditor considers cybersecurity risk; understanding the role of management and responsibilities of the financial statement auditor related to cybersecurity disclosures; understanding management’s approach to cybersecurity risk management; and understanding how CPA firms can assist boards of directors in their oversight of cybersecurity risk management.

Along with questions, the document includes cybersecurity-related resources from the CAQ, the American Institute of CPAs, the National Association of Corporate Directors, and other organizations.

“Boards of directors face an enormous challenge in overseeing how their companies manage cybersecurity risk,” said CAQ executive director Cindy Fornelli in a statement. “Our tool can help foster dialogue that is crucial to addressing cybersecurity challenges and to establishing a clear understanding of cybersecurity roles and responsibilities. As boards tackle this oversight challenge, they have a valuable resource in CPAs and in the public company auditing profession. CPAs bring deep expertise in providing independent assurance services and have assisted companies with information security for decades.”

The publication points out that CPA firms have played a role in assisting companies with information security for decades, and four of the leading 13 information security and cybersecurity consultants are public accounting firms. This publication isn’t intended to provide an all-inclusive list of questions or to be seen as a checklist. Instead it offers examples of the types of questions board members might ask of management and the company’s auditors.

Center for Audit Quality executive director Cindy Fornelli at the CAQ's 10th anniversary event
Darren S. Higgins/Darren S. Higgins

For reprint and licensing requests for this article, click here.
Cyber security Risk management Audit CAQ
MORE FROM ACCOUNTING TODAY

A federal appeals court has ruled unconstitutional a provision of a Maryland law that prevents companies from displaying a digital ad tax charge on a bill.

August 15
2 Min Read
Welcome to Maryland sign cropped

The Internal Revenue Service didn't do enough to verify the identity of callers to its Practitioner Priority Service and Business Specialty Tax phone lines.

August 15
3 Min Read
irs-building-shadows.jpg

The Internal Revenue Service has acknowledged in a court filing that it is now sharing taxpayer data with Immigration and Customs Enforcement.

August 15
1 Min Read
irs-indoor-sign.jpg

Three-quarters of seniors described the 2024-2025 tax season as "somewhat" or "extremely" stressful, according to a Distinct survey.

August 15
1 Min Read
Lazy workers

Plus, Avalara announces Dallas, Atlanta tour dates; Thredd joins Mastercard Wholesale Program; and other accounting tech news.

August 15
1 Min Read
Time management, clock, team

KPMG announces new slate of line of business and U.S. sector leaders; RubinBrown promotes 17 partners across three offices; and more news from across the profession.

August 15
1 Min Read
EY award in California.jpg