A friend in the business sector recently asked me for advice on "IT security in a large charity". Being a developer not specialized in security, I could see his difficulty in finding someone qualified to hire to counsel him.
Struggling for answers, the only example I could advance was the following: if you're seriously asked to give out your password for an audit to be conducted (and this not being a "test", of course), you're probably dealing with someone who doesn't know what they're doing.
What are some helpful tips and pointers you could give a non-technical manager in choosing a competent / avoiding choosing (and hiring) an incompetent professional?
I am aware this question might be off-topic, but the purpose of this question is to give some general resources to non-technical decision makers to hire someone qualified.