Security Audit

A Security Audit is an independent check of controls, policies, and practices against a defined standard. Internal audits come from the organization’s own audit function; external audits bring in an independent third party. Either way, the goal is evidence that controls exist, actually work, and satisfy the requirements they are meant to meet.

Auditors gather that evidence through document review, interviews, direct observation, and testing, then report findings and recommendations. Audits vary by focus: compliance audits check against a regulation, operational audits examine security processes, and technical audits dig into system configurations. Independence is the quality that makes the result credible, which is why the person auditing a control should never be the person who built or runs it. Frameworks like SOC 2 and ISO 27001 often set the criteria being tested. A useful audit closes the loop by tracking each finding through to remediation rather than filing the report and moving on.

How is a security audit tested on the CISSP?

Audit processes sit in Domain 6: Security Assessment and Testing, with governance ties back to risk management. Know internal versus external audits, why auditor independence matters, and how to respond to findings.