From the course: ISC2 Certified Information Systems Security Professional (CISSP) (2024) Cert Prep

Unlock this course with a free trial

Join today to access over 23,400 courses taught by industry experts.

Audits and assessments

Audits and assessments

- [Instructor] Audits and assessments provide organizations with the opportunity to evaluate their security controls to ensure that they're functioning properly and effectively protecting the confidentiality, integrity, and availability of information and systems. Audits and assessments are similar in purpose and function. Both involve evaluating security controls, reporting on their effectiveness, and making recommendations for improvement. The main difference is in the purpose of the review. Assessments are generally performed by or requested by an organization's IT staff. Audits are formal examinations generally performed at the request of someone else, such as a regulator, executive, or board of directors. When an organization undergoes an audit, the auditors follow a formal audit standard and perform planned tests that are designed to determine how well the organization complies with the standard. No matter what type of audit or assessment is taking place, the engagement should…

Contents