Security+Program management
Audits and assessments
Outline only. An audit checks against a criterion. An assessment is a broader look. Neither is a pentest by default.
8 min read · Outline, not a finished note
Outline. This module is on the map so you can track it. The page below is a writing checklist, not finished study material.
Objectives
- Contrast audit, assessment, and penetration test
- Note what evidence means in this context
TODO
Finished note should stay at definitions. No audit-evasion content.
Checklist
- An audit compares practice to a criterion and produces findings. Independence of the auditor is part of why it is trusted.
- An assessment can be internal and advisory. A risk assessment is not automatically an audit.
- A vulnerability scan and a penetration test are technical assessments with different depths. They are defined in the vulnerability-management note. They require authorization, which is the governance note.
- Evidence is the record that shows the control operated: a ticket, a log, a review sign-off. A policy alone is not evidence the control ran.
- Findings need an owner and a response: fix, compensate, or formally accept. That loops back to risk management.