How much overlap is there between IT SOX/SOC 1 audit and Cybersecurity (NIST, ISO, HIPAA, SOC 2) audit? With that background, is it typically easy to pick up cyber?

like
Posting as :
works at
You are currently posting as works at

Hello!

There’s definitely some overlap between IT SOX/SOC 1 audits and cybersecurity audits like NIST, ISO 27001, HIPAA, and SOC 2. Both focus on controls—design and operating effectiveness—but with slightly different priorities.

SOX/SOC 1 is more about financial reporting controls, making sure processes related to financial data are solid.

Cybersecurity frameworks, on the other hand, take a broader view, focusing on operational, privacy, and security risks.

That said, the common ground is significant—things like risk assessments, access controls, change management, and monitoring all apply. If you’ve worked on SOX/SOC 1, you already understand how to assess and audit controls, which makes picking up cybersecurity much easier. You’d just need to learn the specific frameworks (like the NIST Cybersecurity Framework or ISO 27001) and think beyond financial risks to cover a wider range of security concerns.

If you’ve done ITGCs for SOX/SOC 1, you’ve already got a solid foundation—it’s more of an evolution than a reinvention!

likehelpful

You’re very welcome! I post tips like this and job opportunities from all kinds of businesses and organizations on my LinkedIn page so feel free to follow me

Have a great week!

helpful

Related Posts

Transitioning from line of business familiarity (understanding financial statements) to... real(?) Finance (bonds and cap markets and other debt sales) any advice on books or resources to learn really from step 0?

like

Anyone in Fort Worth? Just moved to the area and looking to build a professional network here

Just spent a whole year doing SOX testing... excited to actually go back into external audit.

like

So I had been working as medical interpreter up to the early part of this year. Today, during an interview, the Director with whom I was interviewing genuinely urged me to consider pursuing a career as a PA or even attempt to go to medical school. I had considered it in passing before but today was about the third or fourth time that someone had earnestly nudged me in that direction. Has anyone here made such a career pivot before? I love working in healthcare, there’s nothing like it.

like

Hi guys, I'm currently working on a freelance project remotely and the contractor is paying me well. But I've been looking for a full time job, I got one but the salary is lesser also their is work from office for 3 days a week without any cab facility. What should I do? Should I take this role?

like

I’m having the hardest time finding a new job. I have 12 years of HR experience, a masters in HR, SHRM certification, and all I keep getting are rejection emails. I’ve never experienced this difficult of a time searching for new opportunities. Is this normal once you hit a certain level in your career or is it just me?

likehelpful

I was just talking to a younger friend who goes to Cal and It seems like the kids these days hate FAANG or at least Amazon and Facebook are not desired at all. I personally don’t see too many issues working at either Amazon or Facebook because I work at Deloitte where I’m sure we have many questionable clients and worked in financial services before. Curious on whether people are thinking about the ethics of their exit company when deciding to move?

likesmartfunny

Hi All,
Just want your suggestion on this to help me decide.
I've been working in QA team for big data project and recently I've got offers from Startup and service based MNC as data engineer for the role of Data Engineer.
I've not worked on the actual development of ETL batches till now but I want to learn and grow gradually.

What kind of organisation would be best for me considering my mental health as well because I take too much stress ?

Thanks 🙏

like

Anybody gone from Accenture to Oracle Consulting Services (OCS)? Wondering what the real differences are in delivery, expectations, career, etc.

like

I’m in tech consulting right now & would be interested to explore areas that it intersects with law besides cybersecurity. Does anyone have any suggestions? Always been interested in law school.

like

Hello Fishes,

I have been working as a Management Consultant from Aug-21.
But the job role isn't what was told to me earlier. Hence looking to switch.
Any Help and Guidance is highly appreciated.

Total Exp- 6+ years
Exp: FMCG (Logistics and Supply Chain), Consulting (Team Lead)
CTC- 18 Lacs
Expected CTC- 25+ Lacs

Thanks In Advance.

like

Adobe digital strategy OR Accenture India customer experience or Deloitte digital in India? Which is a better role? Wlb? Long term growth? Please suggest !!!!Deloitte Accenture India Adobe

I’ve been working in finance strategy / transformation consulting for the last two years and would like to pivot into construction project management. Looking to get some insights of if something like this is even feasible or if anyone else has done something similar.

like

How often office party happens in Deloitte credit risk team??

like

Are there any Business Analyst roles available in Cognizant? I have recently skilled up and want to join at a beginner role, however I am not sure about switching and want to gain some experience with Cognizant only. Currently I am working at Gurgaon location in IOA division.

like

What do people recommend for start-up relevant marketing resources/books/personalities/podcasts?
I have a lot of enterprise marketing experience, but making a jump to a startup and want to get up to speed as quickly as possible.

like
like

Is it more worth it to go into FDD at a regional firm now, or hope that my current big 4 will transfer me come spring 2021?

I'm kind of in the mindset of only doing FDD at big 4, otherwise I'll go straight to industry. Am I being too down on mid-market FDD experience and the related exit ops?

Also, I can't go the route of doing FDD at a different big 4. Already got rejected by all of them cause I'm not in audit (but have CPA).

like

More Posts

Hi all,
Wanted to know the range of salary for consultant specialist role? Yoe 10+

When does the pain go away after a hysteroscopy and HSG? I’m 30 hours past and still in quite a bit of pain on either side of my abdomen.

Hi fishes,
My LWD is 18th July and I chose vendor pickup for my assets(expected pickup is 10th July).
Is there any limitation or chances of facing issues on Not having laptop with me(for other exit clearances).
Also it would be great if someone can give guidance on exit clearances as I'm worried that I will miss out something.
TIA.

like

Hello,
I am curious about the latest challenges your company has faced in supply chain operations for the past few months. Is anyone willing to share?

like

I saw my friends text messages (iPhone) and saw that she was texting a guy she shouldn’t be texting. She told me that the “Maybe” function on her iphone is glitching & the wrong name shows up. Cont.

When your leadership team raves about work life balance at happy hours after 3 drinks in.

Post Photo
likefunny

Hi fishes,
After joining, both laptop and desktop is sent. Is it done for everyone or for specific domain? And does this mean the flexibility of working from anywhere ceases to exist?

like

Is there a calculator that I can put in all my investments and see how it works out in 50 years? I know each brokerage has their own projection thing, but just wondering if there are any other tools where i could combine everything?

Recommendations for ergonomic office chair? Wfh is going to go on for awhile so want to invest. Budget is about $300

like

Thoughts on Deloitte’s M&A Human Capital practice? Thought on Strategy& organization strategy? Should I expect case studies fir Strategy&? Any tips would be helpful.

like

I attended interview in hexaware on sep 24th and cleared all rounds I got a mail from HR to send documents on 29th sep after that no mail no calls.. it has been month.. usually how long hexaware take to release offer

Hi those who are looking for "Talent Acquisition Specialist" and work from home. DM me.

like

Pro tip: live close to poorer people to feel rich. The feelings of wealth are extremely subjective and is mainly based on comparison

likefunny

I'm a recent grad who accepted an entry-level full-time job offer with Capital One. I knew that MBB and other consulting firms rarely ever negotiate salary with new grads, so I didn't with Capital One as well. Was that a mistake? What were the likelihoods that they would have raised my salary? I had no other competing offers at the time

Have you ever taken a pay cut? Do you regret it?

likesmarthelpful
like

Deloitte senior managers - comp? Sales targets if any?

like

What's the typical performance bonus for new experienced hire? Joined in Feb. I'm MBA S&O SC2 if it helps.

like

Anyone at EY know about VBM practice and SM comp?

like

What is the industry salary range for tax analyst position at Bay Area? I have 4 years of big 4 experience.

like

Additional Posts in Cyber Security Bowl

Is there a demand for privacy professionals? Been seeing this discussed more and more recently

like

CCSP (cloud security certification) is it worth to do ?

like

Thinking about getting the AWS Cloud Practitioner certification. Does EY have any amazon resources or training materials that they provide? Any advise from people who have taken it before? Thanks!

like

Views on carbon black as a product?

helpful

Currently stuck in risk but interested in Cyber. Have done one related engagement from a regulatory perspective. But a lot of posts here making me think it’s harder to break into than I expected (non-technical background). If you had a six sigma green belt / supply chain degree/exp., would you still go through the effort of going into Cyber or take easy risk money being offered / easier transition back to supply chain? 2-3 YOE and trying to decide career course, any advice highly appreciated

like

Anyone know what kind of experience or certifications I should be aiming to get if I'm trying to break into a pentest role? I just graduated last year and have about a year of sysadmin experience and am trying to get into it asap. So, I'm already applying/job hunting and probably won't get much replies but. Should I be looking at more security analyst/admin roles first? Going for certs? Getting a masters? Wondering what I can do to improve my chances. TIA

like

Folks, best password manager and why?
Many thanks!

like

Joining a group that specializes in incident response. Any recommendations on things I can do this summer to prepare on fundamentals/certs?

like

Exit opps at a manager level - Big4 vs industry jobs? Security Architect at FAANG vs the normal career path at PwC. If compensation being slightly better at FAANG, which one would you pick and why

like

Cissp cert is as much hard as it seems? Much more than cisa?

like

What does a senior cyber consultant make at EY or other b4 firms Chicago if that makes a difference

like

Has anyone gone through the deloitte cyber risk interview process recently? How many interviews did you have and how was the process?? Salary?

like

Thinking of moving from Big4 cyber to Accenture cyber. Any major differences (other than no channel restrictions).

like

Anyone got insights on IBM Security? Areas of expertise? QoL? Pay, etc.

Any recommended study material for CIPP and/or CIPM (still debating the two)?

Anyone working in Pharma industry?

like

Any BCG Platinion Cyber folks here?
What kinna work do you guys do? Planning to make the switch after 5 years with Uncle D. Wanna hear from you guys about culture, projects and areas of expertise.

like
like

What other professional services firms have people who have technical skills. Most the people I work with are security paper pushers who couldn’t tell you basic security shit.

like

Today I passed CIPP/US, and earned Security+ in early August. Interviewing for a cybersecurity role at Deloitte tomorrow! Super excited! Interested to connect with fish at Deloitte, especially Deloitte Global. Thanks!

like

New to Fishbowl?

Download the Fishbowl app to
unlock all discussions on Fishbowl.
That was just a preview…
Sign Up to see all discussions
  • Discover what it’s like to work at companies from real professionals
  • Get candid advice from people in your field in a safe space
  • Chat and network with other professionals in your field
Sign up in seconds to unlock all discussions on Fishbowl.

Already a user?
Login here

Share

Embed this post

Copy and paste embed code on your site

Preview

Download the
Fishbowl app

See what’s happening in your industry
from the palm of your hand.

A phone with Fishbowl app

Scan your QR code to download
Fishbowl app on your mobile

Download app

Sign up for free to view this conversation on Fishbowl

By continuing you agree to Terms of Use and Privacy Policy

Already have an account? Log in

Sign up for free to continue using Fishbowl

By continuing you agree to Terms of Use(New) and Privacy Policy(New)
Messaging rates may apply

Already have an account? Log in

For account settings, visit Fishbowl on Desktop Browser or

General

Legal