Audits and Assessments
- •
def
- •
examining IT infrastructure, software, and devices to check the effectiveness of policies and procedures, and find vulnerabilities before attackers do — can be performed internally or by a third party
- •
- •
attestation
- •
an auditor provides an opinion on the truth/accuracy of an organization's security posture
- •
- •
internal audits
- •
check compliance with regulatory/industry requirements; overseen by an audit committee, which manages all audits from start to finish; can include self-assessments consolidated into ongoing reports
- •
- •
external audits
- •
may be required by regulation, with the type/frequency defined by that regulation; involve hands-on examination (viewing records, compiling reports) and produce an assessment, potentially with improvement recommendations
- •
- •
related