Probably not. IT has its own procedures for enforcing process compliance [1] that are much less susceptible to deviation and much more efficient.
It's ok if you fail to capture something and need to use less effective methods like checklists. But going to them by default or, like the GP's said, only using them are bad.
(But anyway, the GP was complaining because he was expecting highly valuable customized advice, and instead he got low-value process adherence checks. How you do your adherence checks is a completely different subject.)
Love tools that help, eg checklists, when used right.
But over time they have a very strong tendency to become set-in-stone dogma, at which time they will create a priesthood and a very large dead zone where thinking and flexibility is no longer allowed.
I love when people just add comment for pure sake of commenting. The auditing companies don't get a "cyber security expert" with 40 years of experience, but get undergrads, suit them up and sell them as experts. Because of the checklists, that without knowing anything about the context, are almost useless and generate mostly noise.
No I don't know what a VMM is but it's probably not relevant.
Auditing companies absolutely get cyber security experts. Graduates coming out of University obviously don't have the experience of that of veterans but are in a team of experts with experience in that area.
The checklists and workpapers are a way to ensure that there is a level of standardisation in the work that is being performed. If you have assessed a clients firewall or operating system as a veteran you are encouraged to replicate how you did that in a work paper or checklist to cover bases.
Big 4 auditing firms are some of the best in class when it comes to knowledge sharing. Yes sometimes a junior or a senior might miss something without the context, but that is why humans developed lips to talk through it.
I can't count the amount of times I have challenged what a junior has said, or the conclusion a junior has come to based on what a client has said based on my experience.
I was once a graduate myself and found many glaring gaps through the use of simple checklists. If that's all it takes, then the industry needs to write some of their own.
Bonus points: Critical stuff like meraki licensing or certificates that could be solved with a simple calendar.
This stuff is 90% organizational skills and 10% technical skills. My job as a consultant is mostly on the same level as helping people wash their hands. The typical HN person is used to being on skilled technical teams at companies that build technology as their business, but let me tell you that all your business software consumers are constantly in a dire state from top to bottom.
In large global financial audits, there are many complex accounting systems that run on Unix systems. These systems as part of the financial audit are audited to ensure there is an appropriate level of IT general controls that support the underlying financial statements. I.e. what's stopping the admin from making direct data changes to the underlying database that supports the financial statements.
Furthermore, those traditional accounting firms (Big 4) no longer and haven't for a decade + only provided accounting. These firms have enormous skills in internal audit, governance risk and controls, data science, cyber security, Information Technology etc.