Sample Size matters

GRC compliance image - Continuum GRC solutions for cyber security and audit AI-powered cybersecurity 2025 zero trust ransomware protection supply chain security regulatory compliance operational resilience
0

When considering sampling, several factors must be considered. The main parameter is what is referred to as the Total Population. This simply means, how many instances of supporting evidence are there to sample from for the given timeframe of the audit?

For example, if during an access audit, my total population of employees is 100, and the sample size requirement is for first time audits, a 25% sample is collected according to company policy, it would be incorrect to collect a random 25 samples from that population of 100.

Why?

As the auditor, you need to understand what the employee access classifications are for that population of 100 first.

Let’s say that in that population of 100, 5 employees are executive management, 15 are information technology, 10 are operations management, and the remaining 70 are operations support employees.

Sampling under the 25% rule would then be 2 from executive management, 4 from information technology, 3 from operations management, and 18 from operations support. 27 total samples from an equal distribution of job classifications instead of 25 samples from an unbalanced population sampling.

It is also very important not to overlook third party access in your sampling population.

Michael Peters

Website:

Michael Peters is a prominent cybersecurity expert and entrepreneur, serving as the CEO and founder of Lazarus Alliance, a proactive cybersecurity firm established in 2000, and Continuum GRC, a leading governance, risk, and compliance (GRC) software platform he launched in 2015. A U.S. Air Force veteran with early experience in defensive fire control systems, Peters holds an Executive Juris Doctor in Cyberspace Law, an MBA in IT Management, and numerous certifications including CISSP, CISM, CRISC, and QSA. Recognized as an industry disruptor, he has authored books, thousands of articles, and innovative tools like the IT Audit Machine, helping organizations worldwide achieve compliance and mitigate cyber risks. Based in Scottsdale, Arizona, Peters is also an ISSA Hall of Fame recipient dedicated to advancing information security excellence.