Chapter 9

Reporting & Remediation

Learn how to produce clear, actionable audit reports — from structuring an executive summary for board-level audiences to writing detailed technical findings and tracking remediation through re-testing and closure.

Writing the Audit Report

The Audit Report as the Primary Deliverable

The audit report is the most visible and enduring product of the entire audit engagement. It communicates findings, conclusions, and recommendations to stakeholders who may not have been involved in the day-to-day audit work. A well-written report drives action; a poorly written report is filed away and forgotten. The report must be accurate, clear, objective, and constructive — presenting findings in a way that motivates remediation rather than creating defensiveness. Every statement in the report must be supported by evidence documented in the working papers.

  • Executive Summary: A concise, non-technical overview of the audit scope, key findings, overall risk posture, and priority recommendations. Written for senior leadership and board members who need to understand the big picture without technical details.
  • Scope and Objectives: A clear description of what was audited, the time period covered, the standards or frameworks used as evaluation criteria, and any scope limitations or exclusions.
  • Methodology: A brief description of the audit approach, including the types of testing performed, sampling methods used, and tools employed.
  • Findings and Recommendations: The detailed body of the report, presenting each finding with its condition, criteria, cause, effect, risk rating, and recommendation. This is the most substantial section and should be organized by severity or by domain.
  • Management Response: The auditee's response to each finding, including whether they agree or disagree, their planned remediation actions, responsible parties, and target completion dates.
  • Appendices: Supporting details such as the list of personnel interviewed, documents reviewed, systems tested, and the detailed risk rating methodology used.

Writing Effective Finding Statements

Each finding in the audit report should follow a structured format that clearly communicates what was found, why it matters, and what should be done about it. The most widely used format is the Condition-Criteria-Cause-Effect-Recommendation (CCCER) framework, which provides a logical flow from the observation to the action required. This structure ensures findings are complete, defensible, and actionable.

ElementDescriptionExample
ConditionWhat the auditor found — the factual observation supported by evidenceMFA is not enabled for VPN access. 85 out of 200 employees access the network via VPN without MFA.
CriteriaWhat was expected — the standard, policy, or best practice against which the condition is measuredThe organization's Access Control Policy requires MFA for all remote access methods. NIST SP 800-63B recommends MFA for all remote authentication.
CauseWhy the gap exists — the root cause of the deficiencyMFA was implemented for the portfolio management system but was not extended to VPN access due to a lack of centralized identity management.
EffectThe risk or impact — what could happen if the condition is not remediatedVPN accounts protected only by passwords are vulnerable to credential stuffing, phishing, and brute-force attacks. A compromised VPN account provides full network access.
RecommendationThe specific action to remediate the findingImplement MFA for all VPN connections within 30 days. Consider deploying a centralized identity provider to enforce MFA consistently across all access methods.
When writing findings, use precise, factual language. Avoid vague phrases like 'security could be improved' or 'controls were inadequate.' Instead, state specifically what was found: '12 of 15 sampled access requests lacked documented manager approval as required by the Access Control Policy.' Quantified, specific findings are harder to dispute and easier to remediate.

Executive Summary vs Detailed Findings

Understanding Your Audiences

An audit report serves multiple audiences with different needs. The board of directors and executive leadership need a high-level view of risk posture and strategic implications. IT management needs specific technical findings and actionable recommendations. The compliance team needs to understand regulatory implications and remediation tracking requirements. Writing for multiple audiences requires structuring the report so each audience can find what they need without wading through content intended for others.

AudiencePrimary InterestReport SectionTone and Detail Level
Board / C-SuiteOverall risk posture, business impact, strategic investment needsExecutive SummaryNon-technical, business-focused, 1-2 pages maximum
CISO / Security TeamSpecific control failures, technical root causes, prioritized remediationDetailed FindingsTechnical, specific, evidence-based, actionable
IT OperationsSystems affected, remediation steps, implementation guidanceDetailed Findings + RecommendationsTechnical, step-by-step, system-specific
Compliance / LegalRegulatory gaps, compliance status, legal risk exposureFindings mapped to regulatory requirementsRegulatory language, framework references, risk of penalties
External Auditors / RegulatorsMethodology, evidence sufficiency, professional standards adherenceFull report + Working PapersFormal, standards-based, thoroughly documented

Crafting an Effective Executive Summary

The executive summary is often the only section that board members and C-suite executives read in its entirety. It must convey the essential message in one to two pages: what was evaluated, what the key risks are, and what needs to happen next. The executive summary should not simply list all findings — it should synthesize them into a narrative about the organization's overall security posture and the most important actions needed to reduce risk.

  • Scope Overview: One to two sentences describing what was audited and the period covered.
  • Overall Assessment: A clear statement of the organization's overall security posture — is it strong, adequate, or deficient? Avoid ambiguous language.
  • Key Statistics: Summary metrics such as the total number of findings by severity (e.g., 2 Critical, 5 High, 8 Medium, 3 Low) presented as a visual chart or table.
  • Top Three to Five Risks: The most significant findings summarized in business language, emphasizing the potential impact to the organization rather than technical details.
  • Strategic Recommendations: High-level actions needed, including any resource or investment requirements. Frame recommendations as business decisions, not technical tasks.
  • Positive Observations: Acknowledge areas of strength. A balanced report that recognizes effective controls alongside deficiencies is more credible and better received.
The executive summary should be written last, after all findings are finalized, even though it appears first in the report. Writing it last ensures it accurately reflects the full body of findings and avoids the need for revisions as findings are refined.
Never include technical jargon in the executive summary without explanation. Terms like 'SQL injection,' 'CVSS score,' or 'lateral movement' mean nothing to most board members. Translate technical findings into business risk: instead of 'SQL injection vulnerability in the login page,' write 'A flaw in the customer portal could allow an attacker to access the entire customer database.'

Remediation Tracking & Re-testing

From Findings to Remediation

Issuing the audit report is not the end of the audit process — it is the beginning of remediation. The value of an audit is realized only when findings are remediated and the organization's risk posture improves. Effective remediation tracking ensures that findings do not languish in a report but are assigned to owners, tracked against deadlines, and verified through re-testing. Without structured remediation tracking, audit findings become a recurring annual exercise that identifies the same problems year after year.

Building a Remediation Tracking Process

  • Remediation Plan: For each finding, the management response should include specific remediation actions, the responsible person or team, a target completion date, and any dependencies or resource requirements.
  • Tracking Mechanism: Findings should be tracked in a centralized system — whether a GRC platform, a spreadsheet, or a project management tool — that provides visibility into the status of each finding across the organization.
  • Status Updates: Responsible parties should provide regular status updates on remediation progress. Monthly updates are typical for high-severity findings; quarterly for medium and low.
  • Escalation Process: Define what happens when remediation deadlines are missed. A clear escalation path ensures that overdue findings receive management attention rather than being quietly extended.
  • Risk Acceptance Process: If management decides not to remediate a finding, there should be a formal risk acceptance process requiring documentation of the rationale, the residual risk, and approval by an appropriate authority level (typically a senior executive or the board for high and critical findings).

Re-testing and Closure

When management reports that a finding has been remediated, the auditor should perform re-testing to verify that the remediation was effective. Re-testing applies the same testing procedures used during the original audit to confirm that the control deficiency has been corrected. A finding should not be closed based solely on management's assertion that it has been fixed — independent verification is essential to maintain audit integrity.

  • Use the Same Test: Apply the same testing procedure that identified the original finding. If you sampled access requests and found missing approvals, sample a new set of access requests from the period after remediation to verify approvals are now in place.
  • Verify the Root Cause Fix: Do not just test whether the symptom is gone — verify that the root cause has been addressed. If the finding was orphaned accounts caused by manual offboarding, verify that the automated deactivation process is now working, not just that the specific orphaned accounts were disabled.
  • Document the Re-test: Record the re-testing procedure, evidence obtained, and conclusion in the working papers. The re-test documentation should be as rigorous as the original testing.
  • Close or Escalate: If re-testing confirms effective remediation, close the finding. If re-testing shows the remediation was ineffective or incomplete, keep the finding open and escalate to management with a revised target date.
StageDescriptionResponsible Party
IdentifiedFinding documented in the audit report with risk rating and recommendationAuditor
AcknowledgedManagement response received — agree or disagree, remediation plan documentedManagement
In RemediationRemediation actions are underway with regular status updatesFinding Owner
Remediation CompleteManagement asserts the finding has been fixedFinding Owner
Re-testedAuditor independently verifies the remediation through re-testingAuditor
ClosedRe-testing confirms effective remediation; finding is formally closedAuditor
Beware of 'paper remediation' — where management updates the policy document or creates a new procedure but does not actually implement it in practice. During re-testing, verify that the remediation is operational, not just documented. A new policy without evidence of implementation and enforcement does not close a finding.

Chapter quiz

Reporting & Remediation Quiz

6 questions · passing score 70%

Practice scenario

Drafting Findings for Executive Leadership

You have just completed a cybersecurity audit for NovaTech Industries, a manufacturing company with 1,200 employees and operations across three countries. NovaTech operates industrial control systems (ICS) for its factory floors and has recently migrated its corporate IT infrastructure to Azure. The CISO, Angela Torres, has asked you to prepare the final audit report. The board of directors meeting is in three weeks, and Angela needs the report to support her request for a $2 million cybersecurity budget increase. You have identified 15 findings across the engagement and need to draft the report in a way that is accurate, actionable, and effective for multiple audiences.