Point of View

GRC compliance image - Continuum GRC solutions for cyber security and audit AI-powered cybersecurity 2025 zero trust ransomware protection supply chain security regulatory compliance operational resilience
0

As auditors, we must write our testing narratives and report documentation in the 2nd Person writing style. Be sure you understand the differences between first person (I), second person (you), and third person (narrator), point of view writing styles.

For example, in the following control requirement example:

“The organization develops, documents, and disseminates to [Assignment: organization-defined personnel or roles] an access control policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance.”

An example of an acceptable 2nd person test description for the example control requirement would be:

“The auditor verified through examination of the annually renewed Access Control Policy V2, dated July 4, 2022, approved by the CISO, that all employees, contractors, part-time and temporary workers, and those employed by others to perform work on Client Name premises or who have been granted access to Client Name information or systems, are covered by the policy standard and are required to comply with associated guidelines and procedures.”

In this example, the auditor described the Client’s “People”, “Processes” and “Policy”, but not the “Technologies” to satisfy the requirement.

Michael Peters

Website:

Michael Peters is a prominent cybersecurity expert and entrepreneur, serving as the CEO and founder of Lazarus Alliance, a proactive cybersecurity firm established in 2000, and Continuum GRC, a leading governance, risk, and compliance (GRC) software platform he launched in 2015. A U.S. Air Force veteran with early experience in defensive fire control systems, Peters holds an Executive Juris Doctor in Cyberspace Law, an MBA in IT Management, and numerous certifications including CISSP, CISM, CRISC, and QSA. Recognized as an industry disruptor, he has authored books, thousands of articles, and innovative tools like the IT Audit Machine, helping organizations worldwide achieve compliance and mitigate cyber risks. Based in Scottsdale, Arizona, Peters is also an ISSA Hall of Fame recipient dedicated to advancing information security excellence.