EN: Internal IT audit case study for Botium Toys, a fictional U.S. toy company expanding to the EU.
π Full Audit Report (PDF):
docs/Botium-Toys_Audit.pdf
- Assess IT controls (technical/administrative/physical) and compliance maturity
- Evaluate PCI DSS, GDPR, SOC criteria exposure
- Provide prioritized recommendations (0β90 days)
- Controls: Firewall β Β· DRP β Β· IDS β Β· Encryption β Β· AV β
- PCI DSS: Missing encryption & access controls for cardholder data β
- GDPR: Data inventory/classification missing β Β· Breach notification plan β
- SOC (TSC): Integrity/Availability β Β· Access control/Confidentiality β
graph TD
A[Define Scope & Goals] --> B[Risk Assessment]
B --> C[Controls & Compliance Checklist]
C --> D[Findings & Recommendations]
D --> E[Report & Next Steps]