6.5 Security Audits

CISSP Domain 6 Β· Security Assessment and Testing

6.5 Security Audits

A security audit provides structured assurance by comparing evidence about an organisation, system or process against defined criteria.

The central question is not simply:

"Is this secure?"

It is:

"Does the available evidence demonstrate that the defined security requirements are being satisfied?"

πŸ“

Criteria

Establish what the organisation, system or control should satisfy.

WHAT SHOULD BE?
πŸ”Ž

Evidence

Obtain sufficient information about what actually exists and occurs.

WHAT IS?
βœ…

Conclusion

Compare evidence with criteria and communicate the result.

DOES IT CONFORM?
Current CISSP 6.5 Scope

Conduct or Facilitate Security Audits

Internal

Audits performed within organisational control or on behalf of the organisation.

External

Audits involving parties or perspectives outside normal organisational control.

Third-Party

Audits involving suppliers, service providers, independent auditors, certification bodies or other entities outside enterprise control.

Location

Audit strategy must account for on-premises, cloud and hybrid environments.

6.5 Scope

INTERNAL Inside
EXTERNAL Outside
THIRD-PARTY Independent / supplier
LOCATION On-prem Β· Cloud Β· Hybrid

What Is an Audit?

An audit is a structured and documented process for obtaining objective evidence and evaluating that evidence against defined audit criteria.

Audit Objective β†’ Why Are We Auditing?
Audit Criteria β†’ What Should Be?
Audit Evidence β†’ What Is?
Compare β†’ Conformity / Gap
Conclusion β†’ Audit Report

Audit Logic

CRITERIA What should be?
EVIDENCE What is?
COMPARE Does it match?
REPORT What did we conclude?
Critical Distinction

Assessment vs Test vs Audit

Assessment

Broadly evaluates controls, processes, systems or risk.

HOW EFFECTIVE IS IT?

Test

Exercises a system, mechanism or control and observes actual behaviour.

DOES IT WORK?

Audit

Systematically evaluates evidence against defined audit criteria.

DOES IT CONFORM?

Same control - three perspectives

Requirement: privileged access must use MFA.

Assessment: evaluate whether privileged-access controls provide adequate protection.

Test: attempt to authenticate to a privileged account without MFA.

Audit: compare evidence of privileged authentication against the organisation's MFA policy and required control criteria.

Three Questions

ASSESS Effective?
TEST Works?
AUDIT Conforms?
Audit Principles

What Makes an Audit Credible?

Current ISO audit guidance emphasises several principles that help make audit results trustworthy.

Integrity

Auditors should behave professionally, honestly and responsibly.

Fair Presentation

Findings and conclusions should accurately reflect the audit evidence.

Due Professional Care

Auditors should exercise appropriate judgement and diligence.

Confidentiality

Sensitive information obtained during the audit must be handled appropriately.

Independence

Audit conclusions should be objective and protected from inappropriate influence.

Evidence-Based

Conclusions should be supported by verifiable evidence rather than assumptions.

Risk-Based

Audit effort should reflect significant risks and important objectives.

Audit Quality

INTEGRITY Be trustworthy
INDEPENDENCE Be objective
EVIDENCE Prove conclusions
RISK Focus where it matters

Objective Β· Scope Β· Criteria

These three concepts define what an audit is trying to achieve and the boundaries within which its conclusions are valid.

Audit Objective

Why is the audit being performed?

Example

Determine whether privileged-access management satisfies the organisation's security requirements.

Audit Scope

What systems, processes, locations, organisational units and time periods are included?

Example

Production Windows and Linux administrator accounts in the UK data centres for the previous six months.

Audit Criteria

Which policies, standards, requirements or obligations will evidence be compared against?

Example

Privileged Access Standard v4 and applicable regulatory requirements.

Audit Foundation

OBJECTIVE Why?
SCOPE Where / what?
CRITERIA Against what?
πŸ“ Audit Criteria You cannot meaningfully audit without knowing what should be true

Possible Criteria

Law Regulation Contract Security Policy Technical Standard Control Framework Configuration Baseline Certification Standard
Requirement

"All privileged accounts must be reviewed every 90 days."

Evidence

Audit records show that 14 privileged accounts have not been reviewed for more than 180 days.

Criteria = expected state. Evidence = actual state. Audit = compare them.
Audit Management

Audit Programme vs Individual Audit

Audit Programme

Coordinates multiple audits over time according to organisational objectives, risk and assurance needs.

THE OVERALL PLAN

Individual Audit

A specific audit engagement with defined objective, scope, criteria and timing.

ONE ENGAGEMENT

Annual security audit programme
Q1 IAM Audit Q2 Cloud Audit Q3 Supplier Audit Q4 Recovery Audit

Programme vs Audit

PROGRAMME Many audits
AUDIT One engagement

The Audit Lifecycle

1️⃣ Plan β†’ Objective Β· Scope Β· Criteria
2️⃣ Prepare β†’ People Β· Evidence Β· Schedule
3️⃣ Conduct β†’ Fieldwork
4️⃣ Evaluate β†’ Evidence vs Criteria
5️⃣ Report β†’ Findings + Conclusions
6️⃣ Respond β†’ Corrective Action
7️⃣ Follow Up β†’ Verify Resolution

Audit Lifecycle

PLAN Define it
COLLECT Evidence
COMPARE Criteria
REPORT Conclusion
FOLLOW UP Action
πŸ—ΊοΈ Audit Planning Good audit work begins before evidence collection

Determine

Objective Scope Criteria Risk Auditors Schedule Evidence Needed Sampling Reporting
Poor planning

"Audit cloud security."

Better planning

"Evaluate whether production cloud administrative access for the payments platform conforms to the organisation's privileged-access standard during the period January through June."

Clear objective + clear scope + clear criteria = meaningful audit.
CISSP Context 1

Internal Audits

Internal audits are performed by, or on behalf of, the organisation itself.

Advantages

Organisation Knowledge Regular Access Continuous Improvement Operational Context Follow-Up Access

Challenges

Independence Conflict of Interest Organisational Pressure Familiarity Bias Resource Constraints
Internal does not mean informal.
βš–οΈ Internal Audit Independence The auditor should not simply audit their own work
Weak independence

The cloud engineering team designs a privileged-access control, operates it and performs the formal audit of its own control.

Stronger independence

A separate internal audit or assurance function evaluates the privileged-access control.

Do not mark your own homework when stronger assurance requires independent judgement.
Useful Audit Terminology

First-Party Β· Second-Party Β· Third-Party

Audit standards often classify audits according to the relationship between the auditor and the organisation being audited.

First-Party Audit

The organisation audits itself.

INTERNAL AUDIT

Second-Party Audit

An interested organisation audits another organisation with which it has a relationship.

Example

A bank audits a critical technology supplier.

Third-Party Audit

An independent organisation performs the audit, such as for certification or other independent assurance.

CISSP wording vs audit-standard wording

CISSP 6.5 lists internal, external and third-party as separate audit contexts.

Audit standards may describe both second-party and third-party audits as forms of external audit.

On the CISSP exam, follow the context given in the question.

Party Memory Aid

FIRST Audit ourselves
SECOND Audit a business relationship
THIRD Independent audit
CISSP Context 2

External Audits

External audits involve an auditor, customer, regulator, certification body or other party outside the organisation's normal internal audit structure.

Possible Drivers

Regulation Certification Customer Requirement Contract Independent Assurance Government Oversight
External does not automatically mean better

Assurance depends on independence, competence, appropriate scope, suitable criteria and sufficient evidence.

CISSP Context 3

Third-Party Audits

Modern organisations depend heavily on suppliers, SaaS providers, cloud platforms, managed-service providers and other external parties.

Audit activity may therefore need to evaluate:

The Supplier

Does the provider satisfy required security controls?

Independent Reports

Can existing third-party assurance provide relevant evidence?

Contracts

Does the organisation have sufficient audit and assurance rights?

Shared Responsibilities

Which controls belong to the provider and which belong to the customer?

Outsource service β‰  outsource accountability for understanding risk.
πŸ“œ Right to Audit Assurance requirements should be considered before the contract is signed

Contracts with important suppliers can address how the customer obtains security assurance.

Audit Rights Independent Reports Evidence Access Security Requirements Notification Remediation Subcontractors
Problem

A critical supplier processes sensitive data.

After a security incident, the customer asks to audit the provider.

The contract provides:

no audit or assurance rights.

The best time to negotiate assurance rights is before dependency is created.
πŸ“‘ Can We Rely on Someone Else's Audit? Possibly - but first determine whether it answers your assurance question

Review

Scope Criteria Audit Period Auditor Independence Auditor Competence Exceptions Subservice Providers Current Relevance
Example

A cloud provider gives you an independent assurance report.

The report covers:

Service A in Europe.

Your organisation uses:

Service B in South America.

Audit report exists β‰  your service is in scope.
Third-Party Assurance

SOC Reports

Service Organization Control reports are commonly used to provide assurance about controls at service organisations.

SOC 1

Focuses on controls relevant to user entities' Internal Control over Financial Reporting - ICFR.

FINANCIAL REPORTING

SOC 2

Examines controls relevant to Trust Services Criteria involving areas such as security, availability, processing integrity, confidentiality and privacy.

TRUST SERVICES

SOC 3

Provides a Trust Services Criteria report intended for general use without the same detailed restricted-use information contained in a SOC 2 report.

GENERAL USE

SOC Memory Aid

SOC 1 Financial reporting
SOC 2 Trust Services + detail
SOC 3 Trust Services + general use
SOC 2 β‰  "SOC 2 certification"

SOC 2 is an examination and resulting report rather than a generic security certification awarded to an organisation.

πŸ•’ Type 1 vs Type 2 Point in time versus operation across a period
Type 1

Evaluates control design at a specified point in time.

DESIGN Β· AS OF A DATE

Type 2

Includes evaluation of operating effectiveness across a specified period.

DESIGN + OPERATION Β· OVER TIME

Type 1 question

"Are the controls appropriately designed as of the stated date?"

Type 2 question

"Did the controls operate effectively during the stated period?"

Type 1 vs Type 2

TYPE 1 Point in time
TYPE 2 Period of time
πŸ”— Complementary Controls & Subservice Providers A supplier's report may depend on controls outside the supplier itself

When reviewing third-party assurance, determine whether the report assumes that the customer or another provider performs certain complementary controls.

Provider control

Cloud platform supports MFA.

Customer responsibility

Customer must actually enable MFA for privileged users.

Provider control exists β‰  customer responsibility satisfied.
CISSP Context 4

Location: On-Premises Β· Cloud Β· Hybrid

🏒 On-Premises

Organisation may directly operate facilities, infrastructure, networks, platforms and applications.

☁️ Cloud

Control responsibility is divided between the provider and customer according to the service model and contractual arrangement.

πŸ”„ Hybrid

Audit scope must consider controls operating across both environments and the trust relationships connecting them.

Location

ON-PREM Direct environment
CLOUD Shared responsibility
HYBRID Audit the connection too
🏒 On-Premises Audit Physical and logical evidence may both be directly accessible

Possible Evidence

Server Configurations Network Devices Physical Access Logs Data Centre Controls Change Records Asset Inventory Administrator Accounts
Physical control audit

Policy requires restricted server rooms.

Auditor may review:

Access List Badge Records Visitor Logs Door Controls CCTV Evidence
☁️ Cloud Audit Audit according to responsibility
Provider Responsibilities

Certain physical infrastructure, platform or service controls may be operated by the provider.

Customer Responsibilities

Identities, data, permissions, configurations and workloads may remain partly or entirely the customer's responsibility.

Example

The organisation uses SaaS.

Provider assurance covers:

Physical Data Centre Platform Infrastructure Provider Operations

Internal audit examines:

User Access MFA Configuration Data Handling
Cloud does not remove audit responsibility - it changes where evidence comes from.
πŸ”„ Hybrid Audit Do not audit two environments independently and ignore the trust between them
On-Prem Identity ↔ Cloud Identity
Data Centre ↔ Cloud Workload
Internal Logs ↔ Cloud Logs

Audit the Interfaces

Federation Network Links API Trust Data Flows Logging Administrative Access
Compliant on-prem + compliant cloud β‰  compliant integration.
Audit Evidence

Conclusions Need Evidence

Audit evidence should be sufficient and appropriate to support the conclusion being reached.

Documents

Policies, standards, procedures, contracts and architecture.

Records

Tickets, approvals, reviews, reports and audit trails.

Configuration

Actual system and security-control settings.

Logs

Evidence of events, actions and control operation.

Interview

Explanation from personnel responsible for processes and controls.

Observation

Auditor watches the process or control being performed.

Reperformance

Auditor independently performs or repeats an activity to verify the result where appropriate.

Technical Testing

Security-control tests may provide supporting audit evidence.

πŸ”¬ Evidence Quality Quantity alone does not make evidence persuasive
Relevant

Does the evidence relate to the audit criterion?

Reliable

Can the source and evidence be trusted?

Sufficient

Is there enough evidence to support the conclusion?

Current

Does it relate to the period or state being audited?

Objective

Can it be independently verified?

Traceable

Can the conclusion be traced back to supporting evidence?

Weak evidence

Administrator says: "We always disable former employees immediately."

Stronger evidence

Examine termination records and identity logs, then compare termination timestamps with account-disablement timestamps.

"They told me" may support an audit - but it is rarely the strongest evidence by itself.
πŸ”Ί Corroborate Important Evidence Several evidence sources can provide stronger assurance
Requirement

Privileged access must be approved and reviewed.

Interview β†’ How Process Should Work
Procedure β†’ Documented Requirement
Access System β†’ Actual Accounts
Approval Records β†’ Evidence
Sample β†’ Validate Operation

Evidence

TELL ME Interview
SHOW ME Records
PROVE IT Test / reperformance

Audit Sampling

Auditors frequently cannot inspect every transaction, account, log entry or control occurrence.

A suitable sample may therefore be used to obtain evidence about a larger population.

Population

15,000 privileged-access approvals during the audit period.

Audit

Auditor selects an appropriate sample and verifies:

Correct Approver Business Justification Least Privilege Required Review
Sampling provides evidence about a population - it does not magically inspect every item.
🎲 Sampling Risk A sample may not perfectly represent the entire population

Audit conclusions should account for the fact that selected evidence may not reveal every exception in a larger population.

Poor sampling

Auditor allows the process owner to select:

"our 20 best examples."

Convenient sample β‰  representative sample
Sample according to the audit objective and risk.
Traceability

Audit Trails

An audit trail records events or actions in a way that allows activity to be reconstructed and accountability to be established.

Privileged change
User β†’ Who?
Timestamp β†’ When?
Action β†’ What?
Asset β†’ Where?
Approval β†’ Authorised?
Good audit trails support accountability, investigation and assurance.
πŸ›‘οΈ Protect Audit Evidence Evidence is valuable only if its integrity can be trusted
Access Control Integrity Protection Retention Time Synchronisation Secure Storage Chain of Evidence
Problem

Administrators can change production systems and:

delete the audit records showing what they changed.

An audit trail controlled entirely by the person being audited may require additional safeguards.
Audit Approach

Risk-Based Auditing

Audit resources are limited.

Risk-based auditing focuses greater attention on areas where control failure could create greater organisational harm.

Business Objectives β†’ Critical Processes
Critical Processes β†’ Important Risks
Important Risks β†’ Critical Controls
Critical Controls β†’ Audit Focus
Higher audit priority

Internet banking authentication and payment authorisation.

Potentially lower audit priority

An isolated internal utility with no sensitive information or critical business dependency.

Risk-Based Audit

BUSINESS What matters?
RISK What could fail?
CONTROL What protects it?
AUDIT Does it conform?
🎯 Significance & Materiality Not every deviation has the same importance
Deviation A

One low-risk internal account review completed one day late.

Deviation B

300 privileged administrator accounts have never been reviewed.

Both may represent deviations from the same requirement, but the significance is clearly different.

Audit findings require judgement and risk context - not merely counting exceptions.
πŸšͺ Opening the Audit Establish shared understanding before fieldwork begins

Clarify

Objective Scope Criteria Schedule Contacts Evidence Requests Communication Escalation
Audit should not be a guessing game

The auditee should understand what is being audited and the process that will be followed, subject to the engagement's requirements.

Audit Fieldwork

During fieldwork, auditors obtain and analyse evidence relevant to the audit objectives and criteria.

Interview

Understand how the process is supposed to operate.

Inspect

Review documentation, records, configurations and artefacts.

Observe

Watch the process or control being performed.

Sample

Select evidence from a larger population.

Test

Validate control behaviour where appropriate.

Corroborate

Compare multiple sources of evidence.

Fieldwork

ASK Interview
LOOK Inspect
WATCH Observe
PROVE Test
πŸ—£οΈ Management Statements Are Not Automatically Proof Representations can support an audit but should not replace necessary evidence
Manager says

"All leaver accounts are disabled on the employee's final day."

The auditor should obtain evidence appropriate to the audit objective rather than relying only on the assertion.
Possible supporting evidence
HR Termination Records IAM Logs Account Status Sampled Leavers
Audit Results

Audit Findings

Findings connect audit evidence with the criteria being evaluated.

Criterion β†’ Expected State
Evidence β†’ Observed State
Difference β†’ Finding
Finding β†’ Risk / Significance
Criterion

"Critical security patches must be deployed within 14 days."

Evidence

Twelve internet-facing systems have critical vulnerabilities more than 60 days old.

Finding

Critical patching requirements are not consistently satisfied for internet-facing systems.

βœ… Conformity & Nonconformity Audit terminology depends on the audit framework being used
Conformity

Evidence demonstrates that the relevant requirement is fulfilled.

Nonconformity

Evidence demonstrates that a requirement has not been fulfilled.

Terminology varies

Depending on the audit methodology, issues may be described as findings, exceptions, deficiencies, observations or nonconformities.

Understand the framework being used rather than assuming every audit uses identical labels.

πŸ”— Trace Every Finding to Evidence An audit conclusion should not be based on unexplained opinion
Requirement β†’ Audit Criterion
Evidence β†’ Audit Workpaper
Workpaper β†’ Finding
Finding β†’ Conclusion
Requirement β†’ Evidence β†’ Finding β†’ Conclusion.

Audit Workpapers

Audit documentation records the work performed, evidence obtained and basis for important conclusions.

Audit Plan Evidence Samples Interview Notes Test Results Analysis Findings Conclusions
Why documentation matters

Another qualified reviewer should be able to understand what work was performed and why the auditor reached the conclusion.

Audit Quality

Auditor Competence

Independence alone does not make someone capable of performing a good security audit.

Audit Skills

Evidence gathering, sampling, interviewing and reporting.

Security Knowledge

Understand relevant security risks and controls.

Technology Knowledge

Understand the systems and environments being audited.

Business Knowledge

Understand the importance and context of the processes involved.

Regulatory Knowledge

Understand applicable external obligations where relevant.

Professional Judgement

Evaluate evidence objectively and appropriately.

Strong Auditor

INDEPENDENT Objective
COMPETENT Capable
EVIDENCE-BASED Defensible
⚠️ Conflicts of Interest Independence of mind and appearance both matter
Example

A consultant designs the organisation's entire IAM programme.

The same consultant is then hired to provide an "independent audit" of whether that programme was designed correctly.

Ask whether the auditor could be evaluating their own decisions or have another interest in the audit outcome.
🀝 Validate Findings Before Final Reporting Facts can be challenged without compromising auditor independence
Draft finding

"Database backups are never tested."

Management response

The auditee provides evidence showing a successful recovery test performed two months earlier.

The auditor should:

evaluate the new evidence objectively and correct the finding if necessary.

Auditor independence β‰  refusing to consider new evidence
Reporting

The Audit Report

The report communicates what was audited, the evidence-based findings and the conclusions reached.

Objective

Why was the audit performed?

Scope

What was included and excluded?

Criteria

Against what requirements was evidence evaluated?

Methodology

How was evidence obtained?

Findings

What did the evidence demonstrate?

Risk / Significance

Why do the findings matter?

Limitations

What conclusions should not be drawn?

Conclusion

What overall assurance can be provided?

πŸ”­ Audit Scope Limits the Conclusion Passing one audit does not prove everything is secure
Audit

Scope: privileged-access controls in the finance application.

Conclusion

No material exceptions identified within the audited scope.

Wrong conclusion

"The entire company is secure."

Audit conclusion cannot responsibly extend beyond the evidence and scope.

Audit Compliance β‰  Perfect Security

An organisation can satisfy the criteria examined during an audit and still face other security risks.

Audit criterion

All administrator accounts use MFA.

Result: PASS.

Unrelated vulnerability

A public application contains an unauthenticated remote-code execution vulnerability.

Audit asks whether defined criteria are satisfied. It does not prove that every possible threat has been eliminated.
🏁 Closing the Audit Communicate findings and next steps clearly

Discuss

Scope Evidence Findings Significance Disagreements Next Steps Reporting
Surprises should be factual, not procedural

Material issues may need prompt escalation rather than waiting for final report publication.

Corrective Action

Management Response

Audit identifies and communicates issues.

Management is responsible for determining and implementing an appropriate response according to organisational governance.

Audit Finding β†’ Management Response
Response β†’ Action Plan
Action Plan β†’ Owner + Date
Remediation β†’ Follow-Up
Auditor identifies and evaluates. Management owns corrective action and risk decisions.
πŸ” Audit Follow-Up Finding closed should mean corrective action has actually occurred
Finding β†’ Corrective Action
Management Says Complete β†’ Obtain Evidence
Evidence β†’ Verify
Resolved? β†’ Close
Management says "fixed" β‰  audit issue proven closed.
♻️ Repeated Audit Findings A repeated issue often tells you more than an isolated failure
Year 1

Incomplete administrator access reviews.

Year 2

Incomplete administrator access reviews.

Year 3

Incomplete administrator access reviews.

Repeated finding may indicate failed remediation, weak accountability or a systemic control problem.

Protect Audit Information

Audit reports and workpapers can contain extremely sensitive security information.

Control Weaknesses Vulnerabilities Privileged Accounts Architecture Supplier Weaknesses Regulatory Issues Evidence

Audit Information

CLASSIFY Sensitivity
LIMIT Need-to-know
PROTECT Storage + transfer
RETAIN Requirements
An audit report describing every weak control can become an attacker's roadmap.
Modern Assurance

Continuous Auditing vs Continuous Monitoring

Continuous Monitoring

Management continuously or frequently monitors controls, risk, security state and operational conditions.

MANAGEMENT ACTIVITY

Continuous Auditing

Audit uses automated or frequent techniques to obtain assurance more continuously rather than relying only on periodic engagements.

AUDIT / ASSURANCE ACTIVITY

Continuous

MONITORING Management watches controls
AUDITING Auditor evaluates controls
πŸ€– Automated Audit Evidence Automation can increase coverage and frequency
Traditional

Auditor samples 25 cloud administrator accounts.

Automated

Approved analytics evaluate:

all 8,000 identities

against defined access criteria.

Automation improves scale - not judgement automatically

Auditors still need confidence that the data, logic and criteria underlying automated procedures are reliable.

Practical Scenario

Privileged Access Audit at a Bank

Internal audit wants to determine whether production administrator access is being appropriately controlled.

Objective β†’ Privileged Access Assurance
Criteria β†’ IAM Policy + Security Standard
Scope β†’ Production Administrator Accounts
Population β†’ 1,800 Accounts
Evidence β†’ IAM + HR + PAM + Review Records
Testing β†’ Sample + Automated Analytics
Finding β†’ 23 Accounts Not Recertified
Risk β†’ Excess Privileged Access
Report β†’ Management Action
Follow-Up β†’ Verify Remediation
Criteria β†’ Evidence β†’ Finding β†’ Action.
Cloud Scenario

Auditing a SaaS Service

A company stores sensitive customer information in a SaaS platform.

Provider Infrastructure β†’ Independent Provider Assurance
Provider Report β†’ Review Scope + Period + Exceptions
Customer IAM β†’ Internal Audit
Customer Configuration β†’ Internal Audit
Integration β†’ Audit Data Flow + Federation
Use provider assurance for provider controls. Audit your own responsibilities too.
Third-Party Scenario

"We're SOC 2"

A critical supplier tells the security team:

"Don't worry - we're SOC 2."

The correct response is not simply:

"Great, supplier approved."

Review the Report

Type 1 or Type 2? Which Service? Which Period? Which Locations? Which Criteria? Exceptions? Customer Responsibilities? Subservice Organisations?
Assurance report β‰  automatic assurance for your exact risk.
Hybrid Scenario

Each Side Passed

Internal audit finds:

On-premises IAM controls conform.

Cloud audit finds:

Cloud IAM controls conform.

Nobody audits:

the federation trust connecting them.

Audit components AND important interfaces.
Audit Quality Scenario

The Perfect Audit

Management proudly reports:

"The audit found no issues."

Further investigation reveals:

  • management selected every sample;
  • auditors interviewed only process owners;
  • no technical evidence was examined;
  • the highest-risk system was excluded from scope;
  • the auditor designed the control being audited.
Clean report β‰  strong assurance if independence, scope and evidence are weak.
πŸŽ“ CISSP Scenarios Recognise the audit concept being tested
Scenario 1

An organisation evaluates evidence against its mandatory security policy.

Which activity?

Security audit.

Scenario 2

A security engineer deliberately attempts a prohibited network connection to see whether a firewall blocks it.

Audit or test?

Security control test.

The result may later become audit evidence.

Scenario 3

An auditor needs to determine what constitutes acceptable privileged access.

What should be identified?

Audit criteria.

Scenario 4

An audit is intended to determine whether cloud administrator access satisfies organisational policy.

What does this describe?

Audit objective.

Scenario 5

The audit covers the production cloud tenant but specifically excludes development.

Which concept?

Audit scope.

Scenario 6

The organisation's own audit function reviews security controls.

Which audit type?

Internal / first-party audit.

Scenario 7

A customer audits a critical supplier against contractual security requirements.

Which common audit classification?

Second-party audit.

Scenario 8

An independent certification body audits an organisation.

Which common audit classification?

Third-party audit.

Scenario 9

A team audits the control it designed and operates.

Primary concern?

Independence / conflict of interest.

Scenario 10

An independent auditor has never worked with cloud systems but is assigned to audit a highly complex cloud environment.

Primary concern?

Auditor competence.

Scenario 11

Management says access reviews always occur on time.

What should an auditor seek?

Objective supporting evidence.

Scenario 12

The auditor reviews actual access-review records and compares them with system-account data.

Which audit principle?

Evidence-based auditing.

Scenario 13

A security auditor focuses most effort on internet banking and less on a low-value isolated utility.

Which approach?

Risk-based auditing.

Scenario 14

There are 100,000 transactions in the audit period and the auditor evaluates a representative subset.

Which concept?

Audit sampling.

Scenario 15

The process owner selects only the best examples for the auditor.

Primary concern?

Sample bias / unrepresentative evidence.

Scenario 16

The auditor watches an administrator perform the quarterly access review.

Which evidence technique?

Observation.

Scenario 17

An auditor independently repeats a calculation used to determine access-review compliance.

Which evidence technique?

Reperformance.

Scenario 18

An auditor relies entirely on the administrator saying a control works.

Primary weakness?

Insufficient corroborating evidence.

Scenario 19

The evidence indicates that a mandatory security requirement is not being fulfilled.

What may this represent?

A finding / nonconformity, depending on audit methodology.

Scenario 20

Management produces new valid evidence showing that a draft finding is incorrect.

What should the auditor do?

Evaluate the evidence objectively and revise if appropriate.

Scenario 21

An auditor refuses to consider contrary evidence because changing the finding would "look weak."

Which principle is threatened?

Objectivity / fair presentation.

Scenario 22

An audit concludes that a single tested application meets security requirements.

Management claims the entire organisation is therefore secure.

What is wrong?

The conclusion exceeds the audit scope.

Scenario 23

An organisation successfully passes a compliance audit.

Does that prove no security vulnerability exists?

No.

Scenario 24

A supplier gives the organisation an independent audit report.

What should be reviewed before relying on it?

Scope, criteria, period, auditor, exceptions and relevance.

Scenario 25

A supplier's audit report covers a service the organisation does not actually use.

Is it sufficient assurance for the organisation's service?

Not necessarily.

Scenario 26

The supplier's report expired two years ago.

Which concern?

Timeliness / current relevance.

Scenario 27

A service organisation's report focuses on controls relevant to customers' internal control over financial reporting.

Which report?

SOC 1.

Scenario 28

A service provider produces a detailed report examining controls relevant to security, availability, processing integrity, confidentiality or privacy.

Which report?

SOC 2.

Scenario 29

A Trust Services report is intended for general use rather than containing the more detailed restricted-use SOC 2 information.

Which report?

SOC 3.

Scenario 30

The report evaluates control design at a specified date.

Which type?

Type 1.

Scenario 31

The report evaluates operating effectiveness during a defined period.

Which type?

Type 2.

Scenario 32

A provider's report assumes customers configure their own MFA.

The organisation never enabled MFA.

Can the provider's audit compensate for this?

No.

The customer must satisfy its own complementary responsibility.

Scenario 33

Cloud infrastructure controls are independently audited by the provider, while the customer audits its own cloud identities and permissions.

Which concept?

Audit aligned to shared responsibility.

Scenario 34

On-premises and cloud environments both pass their audits, but nobody examines the federation between them.

What is missing?

Hybrid interface / trust-boundary audit coverage.

Scenario 35

A critical supplier refuses an audit because the contract contains no audit clause.

Which lesson?

Assurance and audit rights should be addressed contractually.

Scenario 36

An audit report lists significant security weaknesses and is emailed to hundreds of employees.

Primary concern?

Confidentiality / inappropriate distribution.

Scenario 37

Management says an audit finding has been resolved.

What should audit consider?

Follow-up evidence verifying corrective action.

Scenario 38

The same audit finding appears for three consecutive years.

What may this indicate?

Ineffective remediation, accountability or a systemic control weakness.

Scenario 39

Audit analytics automatically evaluate every privileged account each week.

Which concept may this support?

Continuous or highly automated auditing.

Scenario 40

The operations team continuously monitors privileged accounts while internal audit periodically evaluates whether that monitoring control is effective.

Which distinction?

Continuous monitoring vs audit assurance.

Scenario 41

Audit software says 100% of users are compliant, but the source IAM database excludes several acquired subsidiaries.

Primary concern?

Audit evidence completeness and reliability.

Scenario 42

A single low-impact account is reviewed one day late, while 200 privileged accounts were never reviewed.

Which concept helps distinguish their importance?

Risk significance / materiality.

Scenario 43

An auditor reaches a conclusion but cannot identify which evidence supports it.

What is missing?

Audit traceability and adequate documentation.

Scenario 44

A regulator requires an independent examination rather than a self-assessment.

Why?

Greater independence and external assurance.

Scenario 45

An organisation focuses audits on areas with the highest potential business impact.

Which principle?

Risk-based auditing.

Scenario 46

Audit finds that policy is documented correctly but employees do not follow it.

What does this demonstrate?

Documentation alone does not prove operational conformity.

Scenario 47

Every required audit was completed this year, but none covered the organisation's newly launched critical AI platform.

Primary problem?

Audit programme scope may no longer reflect organisational risk.

Scenario 48

An auditor identifies a potentially severe issue during fieldwork that could expose customers immediately.

Should the auditor always wait for the final report?

No.

Significant issues may require prompt escalation according to the audit process.

Scenario 49

A cloud provider passes its own independent audit, but the customer's permissions allow every employee administrator access.

Which lesson?

Provider assurance does not prove customer-controlled settings are secure.

Scenario 50

Management asks what makes an audit conclusion defensible.

Best answer?

Appropriate criteria, sufficient reliable evidence, competent auditors and objective evaluation.

CISSP Exam Perspective

Recognise the Clue Words

Compared Against Requirements

Formal assurance.

Audit

Why Audit?

Purpose.

Objective

What Is Included?

Boundary.

Scope

Compared Against What?

Expected requirement.

Criteria

What Proves It?

Support conclusion.

Evidence

Organisation Audits Itself

First party.

Internal Audit

Customer Audits Supplier

Business relationship.

Second-Party Audit

Independent Certification

Outside assurance.

Third-Party Audit

Auditor Built Control

Potential bias.

Independence

Auditor Doesn't Understand Technology

Capability issue.

Competence

Review Subset

Population evidence.

Sampling

Watch Process

Evidence.

Observation

Repeat Calculation

Independent verification.

Reperformance

Management Says It Works

Need support.

Corroborate

Requirement Not Met

Audit issue.

Finding / Nonconformity

Highest Risk First

Focus assurance.

Risk-Based Audit

Financial Reporting Controls

Service organisation.

SOC 1

Trust Services Criteria

Detailed assurance.

SOC 2

Trust Services Β· General Use

Less detailed public/general report.

SOC 3

As of a Date

Design.

Type 1

Across a Period

Operating effectiveness.

Type 2

Cloud Provider Control

Use provider evidence.

Third-Party Assurance

Customer Cloud Configuration

Customer responsibility.

Audit Yourself

On-Prem + Cloud

Include trust connections.

Hybrid Audit

Finding Fixed?

Verify.

Follow-Up

Same Finding Every Year

Deeper problem.

Systemic Weakness

Passed Audit

Does not prove everything.

Scope Matters
⚠️ Common CISSP Mistakes Security audit questions often test scope, evidence and independence
Audit β‰  Penetration Test

A penetration test exercises security through adversarial techniques. An audit evaluates evidence against criteria.

Audit β‰  Assessment

Assessment is broader; audit specifically focuses on systematic evaluation against defined criteria.

Policy Exists β‰  Policy Followed

Audit actual evidence of implementation and operation.

Management Says So β‰  Sufficient Evidence

Corroborate important assertions.

Independent β‰  Competent

Auditor must also understand the relevant subject matter.

Internal β‰  Automatically Biased

Internal auditors can provide meaningful assurance when appropriate organisational independence and objectivity exist.

External β‰  Automatically Independent Enough

Conflicts, relationships and engagement structure still matter.

Auditor Built It β‰  Ideal Independent Auditor

Self-review threats should be considered.

Audit Everything Equally β‰  Risk-Based Auditing

Higher-risk areas generally justify greater audit attention.

Sample β‰  Entire Population

Sampling creates sampling risk and requires appropriate selection.

Process Owner's Best Examples β‰  Representative Sample
Finding Count β‰  Finding Significance

Risk and impact matter.

Passed Audit β‰  Secure Against Everything

An audit provides assurance against its scope and criteria.

No Findings β‰  No Risk

Consider audit scope, methodology and evidence limitations.

SOC 1 β‰  General Cybersecurity Report

SOC 1 concerns controls relevant to internal control over financial reporting.

SOC 2 β‰  SOC 2 Certification

It is an examination and report.

SOC 2 β‰  SOC 3

SOC 3 is intended for general use and does not provide the same detailed information as SOC 2.

Type 1 β‰  Type 2

Type 1 focuses on controls at a point in time.

Type 2 includes operating effectiveness over a period.

Provider Audit Passed β‰  Customer Configuration Secure

Understand shared and complementary responsibilities.

Audit Report Exists β‰  Relevant Audit Report

Review scope, date, service, criteria and findings.

Secure On-Prem + Secure Cloud β‰  Secure Hybrid Integration

Audit trust boundaries and interfaces too.

No Contractual Audit Rights β‰  Easy Supplier Audit

Assurance requirements should be addressed before dependency is established.

Audit Report β‰  Public Document

Reports and evidence may disclose significant security weaknesses.

Management Says Fixed β‰  Finding Verified

Follow-up should obtain appropriate evidence.

Auditor Finds Problem β‰  Auditor Owns Remediation

Management remains responsible for corrective actions and risk decisions.

Continuous Monitoring β‰  Continuous Auditing

Monitoring is typically a management control activity; auditing is an assurance activity.

Quick Reference

If you see...Think...
Evidence compared against requirementsAudit
Why are we auditing?Objective
What's included?Scope
Against what?Criteria
What proves it?Evidence
Organisation audits itselfInternal / First Party
Customer audits supplierSecond Party
Independent certification auditThird Party
Auditor evaluates own workIndependence Concern
Auditor lacks skillsCompetence Concern
Subset of populationSampling
Watch process operateObservation
Repeat procedure independentlyReperformance
Requirement not satisfiedFinding / Nonconformity
Most important risks receive more attentionRisk-Based Audit
Financial reporting controlsSOC 1
Trust Services detailed reportSOC 2
Trust Services general-use reportSOC 3
As of a dateType 1
Operating effectiveness over timeType 2
Supplier assurance reportCheck Scope + Period + Exceptions
Provider controlsThird-Party Assurance
Customer cloud configurationCustomer Audit Responsibility
On-prem + cloudAudit Integration
Auditee says finding fixedFollow-Up Evidence
Same finding repeatedlySystemic / Remediation Problem
Management watches controls continuouslyContinuous Monitoring
Audit obtains assurance continuouslyContinuous Auditing

Audit Memory Aid

OBJECTIVE Why?
SCOPE What?
CRITERIA Against what?
EVIDENCE Proof?
CONCLUSION Result?

Audit Party Memory Aid

FIRST We audit ourselves
SECOND We audit someone we do business with
THIRD Independent party audits

SOC Memory Aid

SOC 1 Financial reporting
SOC 2 Trust Services Β· detailed
SOC 3 Trust Services Β· general use
TYPE 1 Point in time
TYPE 2 Over a period

Location Memory Aid

ON-PREM Audit direct controls
CLOUD Audit shared responsibilities
HYBRID Audit both + connection

6.5 Master Memory Aid

DEFINE Objective Β· Scope Β· Criteria
INDEPENDENCE Trust the auditor
COLLECT Objective evidence
COMPARE Evidence vs criteria
REPORT Findings + conclusion
CORRECT Management response
FOLLOW UP Verify action

Criteria β†’ Evidence β†’ Compare β†’ Conclude

The Security Auditor's Questions

WHY? What is the audit objective?
WHAT? What is in scope?
AGAINST WHAT? What are the criteria?
WHO? Who is performing the audit?
INDEPENDENT? Can they be objective?
COMPETENT? Do they understand the subject?
EVIDENCE? What proves the result?
SUFFICIENT? Do we have enough evidence?
RELIABLE? Can we trust the evidence?
GAP? Does actual state meet expected state?
RISK? How significant is the finding?
ACTION? What will management do?
FOLLOW-UP? Has corrective action been verified?
Domain 6 Complete

How the Five Domain 6 Lessons Fit Together

6.1 Strategy β†’ What assurance do we need?
6.2 Control Testing β†’ Does the control work?
6.3 Process Data β†’ What do the measures tell us?
6.4 Analysis & Reporting β†’ What do the findings mean?
6.5 Audit β†’ Does the evidence satisfy the criteria?

Domain 6

STRATEGY Plan assurance
TEST Exercise controls
MEASURE Collect data
ANALYSE Understand results
AUDIT Compare evidence to criteria

Key Takeaways

CISSP 6.5 focuses on conducting or facilitating security audits.

The current CISSP outline explicitly includes internal, external, third-party and location-based audits covering on-premises, cloud and hybrid environments.

An audit systematically obtains and evaluates evidence against defined audit criteria.

The basic audit relationship is:

Criteria β†’ Evidence β†’ Comparison β†’ Conclusion.

The audit objective explains why the audit is being performed.

Audit scope identifies the systems, processes, locations, organisational units and periods included.

Audit criteria define the policies, standards, laws, contractual obligations or other requirements against which evidence is evaluated.

Objective = why. Scope = what. Criteria = against what.

Assessment, testing and auditing are related but distinct.

Assessment broadly evaluates security effectiveness.

Testing exercises controls and systems.

Auditing compares objective evidence against established criteria.

Assess = effective? Test = works? Audit = conforms?

Credible audits depend on integrity, fair presentation, due professional care, confidentiality, independence and evidence-based evaluation.

Risk-based auditing directs greater assurance effort toward areas where failure could create greater organisational impact.

An audit programme coordinates multiple audits over time, while an individual audit is a specific engagement.

The audit lifecycle generally includes planning, preparation, fieldwork, evidence evaluation, reporting and follow-up.

Internal audits are performed by or on behalf of the organisation itself.

Internal auditors can provide strong assurance when appropriate independence and objectivity exist.

Internal does not mean informal.

First-party audit commonly refers to internal audit.

Second-party audit commonly refers to an interested party auditing an organisation with which it has a relationship, such as a customer auditing a supplier.

Third-party audit commonly refers to an independent auditing organisation, such as a certification body.

First = ourselves. Second = business relationship. Third = independent.

CISSP separately lists internal, external and third-party contexts, while some formal audit terminology groups second- and third-party activity under external auditing.

Auditor independence reduces the risk that conclusions are improperly influenced by responsibility for the activity being audited.

An auditor who designed or operates the control may create a self-review concern.

Independence alone is not enough.

Auditors must also have sufficient competence to understand the audit methodology, technology, business environment and applicable criteria.

Independent + competent + evidence-based = stronger assurance.

Third-party audits are particularly important where organisations depend on suppliers, cloud services, SaaS platforms and managed-service providers.

Contracts can establish audit rights, evidence requirements and assurance obligations before dependency on a supplier is created.

Existing third-party audit reports can provide useful assurance, but their scope, criteria, period, independence, exceptions and relevance should be evaluated before relying on them.

Audit report exists β‰  audit report covers your risk.

SOC reports are commonly used to provide assurance regarding controls at service organisations.

SOC 1 concerns controls relevant to user entities' internal control over financial reporting.

SOC 2 addresses controls relevant to Trust Services Criteria involving security, availability, processing integrity, confidentiality and privacy.

SOC 3 also relates to Trust Services Criteria but provides a general-use report rather than the detailed restricted-use information associated with SOC 2.

SOC 1 = financial reporting. SOC 2 = Trust Services detailed report. SOC 3 = Trust Services general-use report.

SOC 2 should not be described as a generic "SOC 2 certification."

Type 1 reports evaluate controls at a specified point in time.

Type 2 reports include evaluation of operating effectiveness during a defined period.

Type 1 = point in time. Type 2 = over time.

Third-party reports may depend on complementary controls that the customer is responsible for implementing.

Provider assurance does not prove that customer-controlled identities, configurations or permissions are secure.

Cloud audits therefore require an understanding of shared responsibility.

Hybrid audits should evaluate not only on-premises and cloud controls but also the federation, network connectivity, APIs, data flows and other trust relationships connecting them.

Secure A + Secure B β‰  Secure A-to-B relationship.

Audit conclusions require appropriate evidence.

Evidence may include documentation, records, logs, configurations, interviews, observations, technical tests and reperformance.

Important assertions can be corroborated using multiple evidence sources.

Management statements can provide useful information, but significant conclusions should normally be supported by appropriate objective evidence.

Audit evidence should be relevant, reliable, sufficient, current and traceable to the conclusion it supports.

Tell me β†’ Show me β†’ Prove it.

Sampling can be used where testing every item in a population is impractical.

Sampling introduces the possibility that the selected items do not perfectly represent the wider population.

Allowing an auditee to provide only its best examples can undermine the reliability of the sample.

Audit trails support accountability by recording who performed an action, what happened, when it happened and where it occurred.

Audit trails and other audit evidence should themselves be protected against inappropriate modification or deletion.

Audit findings connect the expected state defined by criteria with the actual state demonstrated by evidence.

Depending on the audit framework, deviations may be described using terms such as findings, exceptions, deficiencies, observations or nonconformities.

Terminology can vary; evidence and criteria are what matter.

Audit documentation and workpapers record the procedures performed, evidence obtained and basis for conclusions.

Significant findings should be traceable to the evidence supporting them.

Risk and significance should be considered rather than treating every audit deviation as equally important.

Audit reports should describe objective, scope, criteria, methodology, findings, limitations and conclusions as appropriate.

Audit scope constrains the conclusion.

Passing one security audit does not demonstrate that every system, control or threat across the organisation has been evaluated.

Compliance with audited criteria β‰  absence of all security risk.

Management should have an opportunity to provide relevant evidence and factual clarification before findings are finalised.

Auditor independence does not mean refusing to correct a finding when better evidence demonstrates that it is wrong.

Management is normally responsible for corrective action and risk decisions arising from audit findings.

Follow-up provides evidence that agreed corrective action actually occurred.

Management says fixed β‰  auditor has verified closure.

Repeated findings can indicate ineffective remediation, inadequate accountability or systemic control weaknesses.

Audit reports and workpapers can reveal sensitive information about vulnerabilities, control gaps, architecture and third-party weaknesses and should therefore be appropriately protected.

Continuous monitoring and continuous auditing are different concepts.

Continuous monitoring is generally a management activity that observes control and risk conditions.

Continuous auditing uses recurring or automated audit procedures to provide assurance more frequently.

Automation can increase audit coverage and frequency, but auditors still need to establish that data sources, automated logic and audit criteria are reliable.

The central CISSP principle is: define what should be true, obtain trustworthy evidence of what is actually true, evaluate the difference objectively and communicate the resulting assurance to the people who need it.

πŸ“š Sources & Further Reading Current audit, security-assurance and service-organisation references