Skip to content
Jon MarienStudy Desk

Security+Program management

Audits and assessments

Outline only. An audit checks against a criterion. An assessment is a broader look. Neither is a pentest by default.

8 min read · Outline, not a finished note

Outline. This module is on the map so you can track it. The page below is a writing checklist, not finished study material.

Objectives

  • Contrast audit, assessment, and penetration test
  • Note what evidence means in this context
On this page
  1. TODO
  2. Checklist

TODO

Finished note should stay at definitions. No audit-evasion content.

Checklist

  • An audit compares practice to a criterion and produces findings. Independence of the auditor is part of why it is trusted.
  • An assessment can be internal and advisory. A risk assessment is not automatically an audit.
  • A vulnerability scan and a penetration test are technical assessments with different depths. They are defined in the vulnerability-management note. They require authorization, which is the governance note.
  • Evidence is the record that shows the control operated: a ticket, a log, a review sign-off. A policy alone is not evidence the control ran.
  • Findings need an owner and a response: fix, compensate, or formally accept. That loops back to risk management.

More on this track