Trust but Verify

GRC slider image - discover Continuum GRC ITAM for automated compliance AI-powered cybersecurity 2025 zero trust ransomware protection supply chain security regulatory compliance operational resilience
0

Never take the customer’s word for anything. Your job as an auditor is to prove that the control requirements are implemented and functioning satisfactorily.

We are not assuming that clients lie to us. It is our professional reputation that gets damaged if we fail to correctly verify the implementation status of a control requirement.

Evidence is the proof that the control requirement implementation description is true and accurate.

As an auditor, you must determine what constitutes a good piece of evidence.

The fundamental elements to this task are as follows:

Michael Peters

Website:

Michael Peters is a prominent cybersecurity expert and entrepreneur, serving as the CEO and founder of Lazarus Alliance, a proactive cybersecurity firm established in 2000, and Continuum GRC, a leading governance, risk, and compliance (GRC) software platform he launched in 2015. A U.S. Air Force veteran with early experience in defensive fire control systems, Peters holds an Executive Juris Doctor in Cyberspace Law, an MBA in IT Management, and numerous certifications including CISSP, CISM, CRISC, and QSA. Recognized as an industry disruptor, he has authored books, thousands of articles, and innovative tools like the IT Audit Machine, helping organizations worldwide achieve compliance and mitigate cyber risks. Based in Scottsdale, Arizona, Peters is also an ISSA Hall of Fame recipient dedicated to advancing information security excellence.