Purpose for the Security Audit and Assessment
The security audit and assessment identifies vulnerabilities, validates controls, strengthens defenses, and ensures systems, data, infrastructure, and processes meet standards and resist evolving threats.
3 slides · 2 min read · Domain 6
The audit profession has a well-established body of practice, with its own language and professional expectations.
Audit practices have increasingly addressed risks in other areas, including expectations for privacy, information protection, business process improvement, organizational culture, and ethical behavior.
The audit community has applied its established practices to the management of information systems risk, as the information systems community was developing a body of practice for information security. To align the disciplines, organizations developed standards to codify best practices. While these standards reflect the requirements of unique business problems, they often use different terms to describe the same activity. Navigating this language can often be confusing for people just starting out, so it is important that we have a common understanding of key terms and concepts.
Security assessments, audits, tests, or other activities can be formal or informal.
- Formal. The audit, test, or other assessment activity is an evaluation against a compliance standard, which may be a legal, regulatory, or contracts requirement. Formal audits are performed by individuals outside the management structure of
the organization that owns, operates, or is responsible for the systems being evaluated. This independence is essential to ensure there is no l undue management influence in the evaluation's conduct, which would skew the evaluator's judgment.
- Informal. The audit, test, or other assessment activity is conducted to provide insights into and observations about the systems being evaluated, but not for the direct purpose of meeting a compliance requirement. Informal evaluations can be conducted using the same compliance standards as used in a formal evaluation, or against a subset of those requirements. In-house personnel, third-party evaluators, or a mix of talent can perform informal evaluations. Informal evaluations are often performed to give management a preliminary view of what a formal evaluation may reveal, providing actionable findings prior to the next compliance-related activity.
