6.5 Security Audits
6.5 Security Audits
A security audit provides structured assurance by comparing evidence about an organisation, system or process against defined criteria.
The central question is not simply:
"Is this secure?"
It is:
"Does the available evidence demonstrate that the defined security requirements are being satisfied?"
Criteria
Establish what the organisation, system or control should satisfy.
WHAT SHOULD BE?Evidence
Obtain sufficient information about what actually exists and occurs.
WHAT IS?Conclusion
Compare evidence with criteria and communicate the result.
DOES IT CONFORM?Conduct or Facilitate Security Audits
Audits performed within organisational control or on behalf of the organisation.
Audits involving parties or perspectives outside normal organisational control.
Audits involving suppliers, service providers, independent auditors, certification bodies or other entities outside enterprise control.
Audit strategy must account for on-premises, cloud and hybrid environments.
6.5 Scope
What Is an Audit?
An audit is a structured and documented process for obtaining objective evidence and evaluating that evidence against defined audit criteria.
Audit Logic
Assessment vs Test vs Audit
Broadly evaluates controls, processes, systems or risk.
HOW EFFECTIVE IS IT?
Exercises a system, mechanism or control and observes actual behaviour.
DOES IT WORK?
Systematically evaluates evidence against defined audit criteria.
DOES IT CONFORM?
Requirement: privileged access must use MFA.
Assessment: evaluate whether privileged-access controls provide adequate protection.
Test: attempt to authenticate to a privileged account without MFA.
Audit: compare evidence of privileged authentication against the organisation's MFA policy and required control criteria.
Three Questions
What Makes an Audit Credible?
Current ISO audit guidance emphasises several principles that help make audit results trustworthy.
Auditors should behave professionally, honestly and responsibly.
Findings and conclusions should accurately reflect the audit evidence.
Auditors should exercise appropriate judgement and diligence.
Sensitive information obtained during the audit must be handled appropriately.
Audit conclusions should be objective and protected from inappropriate influence.
Conclusions should be supported by verifiable evidence rather than assumptions.
Audit effort should reflect significant risks and important objectives.
Audit Quality
Objective Β· Scope Β· Criteria
These three concepts define what an audit is trying to achieve and the boundaries within which its conclusions are valid.
Why is the audit being performed?
Determine whether privileged-access management satisfies the organisation's security requirements.
What systems, processes, locations, organisational units and time periods are included?
Production Windows and Linux administrator accounts in the UK data centres for the previous six months.
Which policies, standards, requirements or obligations will evidence be compared against?
Privileged Access Standard v4 and applicable regulatory requirements.
Audit Foundation
π Audit Criteria You cannot meaningfully audit without knowing what should be true
Possible Criteria
"All privileged accounts must be reviewed every 90 days."
Audit records show that 14 privileged accounts have not been reviewed for more than 180 days.
Audit Programme vs Individual Audit
Coordinates multiple audits over time according to organisational objectives, risk and assurance needs.
THE OVERALL PLAN
A specific audit engagement with defined objective, scope, criteria and timing.
ONE ENGAGEMENT
Programme vs Audit
The Audit Lifecycle
Audit Lifecycle
πΊοΈ Audit Planning Good audit work begins before evidence collection
Determine
"Audit cloud security."
"Evaluate whether production cloud administrative access for the payments platform conforms to the organisation's privileged-access standard during the period January through June."
Internal Audits
Internal audits are performed by, or on behalf of, the organisation itself.
Advantages
Challenges
βοΈ Internal Audit Independence The auditor should not simply audit their own work
The cloud engineering team designs a privileged-access control, operates it and performs the formal audit of its own control.
A separate internal audit or assurance function evaluates the privileged-access control.
First-Party Β· Second-Party Β· Third-Party
Audit standards often classify audits according to the relationship between the auditor and the organisation being audited.
The organisation audits itself.
INTERNAL AUDIT
An interested organisation audits another organisation with which it has a relationship.
A bank audits a critical technology supplier.
An independent organisation performs the audit, such as for certification or other independent assurance.
CISSP 6.5 lists internal, external and third-party as separate audit contexts.
Audit standards may describe both second-party and third-party audits as forms of external audit.
On the CISSP exam, follow the context given in the question.
Party Memory Aid
External Audits
External audits involve an auditor, customer, regulator, certification body or other party outside the organisation's normal internal audit structure.
Possible Drivers
Assurance depends on independence, competence, appropriate scope, suitable criteria and sufficient evidence.
Third-Party Audits
Modern organisations depend heavily on suppliers, SaaS providers, cloud platforms, managed-service providers and other external parties.
Audit activity may therefore need to evaluate:
Does the provider satisfy required security controls?
Can existing third-party assurance provide relevant evidence?
Does the organisation have sufficient audit and assurance rights?
Which controls belong to the provider and which belong to the customer?
π Right to Audit Assurance requirements should be considered before the contract is signed
Contracts with important suppliers can address how the customer obtains security assurance.
A critical supplier processes sensitive data.
After a security incident, the customer asks to audit the provider.
The contract provides:
no audit or assurance rights.
π Can We Rely on Someone Else's Audit? Possibly - but first determine whether it answers your assurance question
Review
A cloud provider gives you an independent assurance report.
The report covers:
Service A in Europe.
Your organisation uses:
Service B in South America.
SOC Reports
Service Organization Control reports are commonly used to provide assurance about controls at service organisations.
Focuses on controls relevant to user entities' Internal Control over Financial Reporting - ICFR.
FINANCIAL REPORTING
Examines controls relevant to Trust Services Criteria involving areas such as security, availability, processing integrity, confidentiality and privacy.
TRUST SERVICES
Provides a Trust Services Criteria report intended for general use without the same detailed restricted-use information contained in a SOC 2 report.
GENERAL USE
SOC Memory Aid
SOC 2 is an examination and resulting report rather than a generic security certification awarded to an organisation.
π Type 1 vs Type 2 Point in time versus operation across a period
Evaluates control design at a specified point in time.
DESIGN Β· AS OF A DATE
Includes evaluation of operating effectiveness across a specified period.
DESIGN + OPERATION Β· OVER TIME
"Are the controls appropriately designed as of the stated date?"
"Did the controls operate effectively during the stated period?"
Type 1 vs Type 2
π Complementary Controls & Subservice Providers A supplier's report may depend on controls outside the supplier itself
When reviewing third-party assurance, determine whether the report assumes that the customer or another provider performs certain complementary controls.
Cloud platform supports MFA.
Customer must actually enable MFA for privileged users.
Location: On-Premises Β· Cloud Β· Hybrid
Organisation may directly operate facilities, infrastructure, networks, platforms and applications.
Control responsibility is divided between the provider and customer according to the service model and contractual arrangement.
Audit scope must consider controls operating across both environments and the trust relationships connecting them.
Location
π’ On-Premises Audit Physical and logical evidence may both be directly accessible
Possible Evidence
Policy requires restricted server rooms.
Auditor may review:
βοΈ Cloud Audit Audit according to responsibility
Certain physical infrastructure, platform or service controls may be operated by the provider.
Identities, data, permissions, configurations and workloads may remain partly or entirely the customer's responsibility.
The organisation uses SaaS.
Provider assurance covers:
Internal audit examines:
π Hybrid Audit Do not audit two environments independently and ignore the trust between them
Audit the Interfaces
Conclusions Need Evidence
Audit evidence should be sufficient and appropriate to support the conclusion being reached.
Policies, standards, procedures, contracts and architecture.
Tickets, approvals, reviews, reports and audit trails.
Actual system and security-control settings.
Evidence of events, actions and control operation.
Explanation from personnel responsible for processes and controls.
Auditor watches the process or control being performed.
Auditor independently performs or repeats an activity to verify the result where appropriate.
Security-control tests may provide supporting audit evidence.
π¬ Evidence Quality Quantity alone does not make evidence persuasive
Does the evidence relate to the audit criterion?
Can the source and evidence be trusted?
Is there enough evidence to support the conclusion?
Does it relate to the period or state being audited?
Can it be independently verified?
Can the conclusion be traced back to supporting evidence?
Administrator says: "We always disable former employees immediately."
Examine termination records and identity logs, then compare termination timestamps with account-disablement timestamps.
πΊ Corroborate Important Evidence Several evidence sources can provide stronger assurance
Privileged access must be approved and reviewed.
Evidence
Audit Sampling
Auditors frequently cannot inspect every transaction, account, log entry or control occurrence.
A suitable sample may therefore be used to obtain evidence about a larger population.
15,000 privileged-access approvals during the audit period.
Auditor selects an appropriate sample and verifies:
π² Sampling Risk A sample may not perfectly represent the entire population
Audit conclusions should account for the fact that selected evidence may not reveal every exception in a larger population.
Auditor allows the process owner to select:
"our 20 best examples."
Audit Trails
An audit trail records events or actions in a way that allows activity to be reconstructed and accountability to be established.
π‘οΈ Protect Audit Evidence Evidence is valuable only if its integrity can be trusted
Administrators can change production systems and:
delete the audit records showing what they changed.
Risk-Based Auditing
Audit resources are limited.
Risk-based auditing focuses greater attention on areas where control failure could create greater organisational harm.
Internet banking authentication and payment authorisation.
An isolated internal utility with no sensitive information or critical business dependency.
Risk-Based Audit
π― Significance & Materiality Not every deviation has the same importance
One low-risk internal account review completed one day late.
300 privileged administrator accounts have never been reviewed.
Both may represent deviations from the same requirement, but the significance is clearly different.
πͺ Opening the Audit Establish shared understanding before fieldwork begins
Clarify
The auditee should understand what is being audited and the process that will be followed, subject to the engagement's requirements.
Audit Fieldwork
During fieldwork, auditors obtain and analyse evidence relevant to the audit objectives and criteria.
Understand how the process is supposed to operate.
Review documentation, records, configurations and artefacts.
Watch the process or control being performed.
Select evidence from a larger population.
Validate control behaviour where appropriate.
Compare multiple sources of evidence.
Fieldwork
π£οΈ Management Statements Are Not Automatically Proof Representations can support an audit but should not replace necessary evidence
"All leaver accounts are disabled on the employee's final day."
Audit Findings
Findings connect audit evidence with the criteria being evaluated.
"Critical security patches must be deployed within 14 days."
Twelve internet-facing systems have critical vulnerabilities more than 60 days old.
Critical patching requirements are not consistently satisfied for internet-facing systems.
β Conformity & Nonconformity Audit terminology depends on the audit framework being used
Evidence demonstrates that the relevant requirement is fulfilled.
Evidence demonstrates that a requirement has not been fulfilled.
Depending on the audit methodology, issues may be described as findings, exceptions, deficiencies, observations or nonconformities.
Understand the framework being used rather than assuming every audit uses identical labels.
π Trace Every Finding to Evidence An audit conclusion should not be based on unexplained opinion
Audit Workpapers
Audit documentation records the work performed, evidence obtained and basis for important conclusions.
Another qualified reviewer should be able to understand what work was performed and why the auditor reached the conclusion.
Auditor Competence
Independence alone does not make someone capable of performing a good security audit.
Evidence gathering, sampling, interviewing and reporting.
Understand relevant security risks and controls.
Understand the systems and environments being audited.
Understand the importance and context of the processes involved.
Understand applicable external obligations where relevant.
Evaluate evidence objectively and appropriately.
Strong Auditor
β οΈ Conflicts of Interest Independence of mind and appearance both matter
A consultant designs the organisation's entire IAM programme.
The same consultant is then hired to provide an "independent audit" of whether that programme was designed correctly.
π€ Validate Findings Before Final Reporting Facts can be challenged without compromising auditor independence
"Database backups are never tested."
The auditee provides evidence showing a successful recovery test performed two months earlier.
The auditor should:
evaluate the new evidence objectively and correct the finding if necessary.
The Audit Report
The report communicates what was audited, the evidence-based findings and the conclusions reached.
Why was the audit performed?
What was included and excluded?
Against what requirements was evidence evaluated?
How was evidence obtained?
What did the evidence demonstrate?
Why do the findings matter?
What conclusions should not be drawn?
What overall assurance can be provided?
π Audit Scope Limits the Conclusion Passing one audit does not prove everything is secure
Scope: privileged-access controls in the finance application.
No material exceptions identified within the audited scope.
"The entire company is secure."
Audit Compliance β Perfect Security
An organisation can satisfy the criteria examined during an audit and still face other security risks.
All administrator accounts use MFA.
Result: PASS.
A public application contains an unauthenticated remote-code execution vulnerability.
π Closing the Audit Communicate findings and next steps clearly
Discuss
Material issues may need prompt escalation rather than waiting for final report publication.
Management Response
Audit identifies and communicates issues.
Management is responsible for determining and implementing an appropriate response according to organisational governance.
π Audit Follow-Up Finding closed should mean corrective action has actually occurred
β»οΈ Repeated Audit Findings A repeated issue often tells you more than an isolated failure
Incomplete administrator access reviews.
Incomplete administrator access reviews.
Incomplete administrator access reviews.
Protect Audit Information
Audit reports and workpapers can contain extremely sensitive security information.
Audit Information
Continuous Auditing vs Continuous Monitoring
Management continuously or frequently monitors controls, risk, security state and operational conditions.
MANAGEMENT ACTIVITY
Audit uses automated or frequent techniques to obtain assurance more continuously rather than relying only on periodic engagements.
AUDIT / ASSURANCE ACTIVITY
Continuous
π€ Automated Audit Evidence Automation can increase coverage and frequency
Auditor samples 25 cloud administrator accounts.
Approved analytics evaluate:
all 8,000 identities
against defined access criteria.
Auditors still need confidence that the data, logic and criteria underlying automated procedures are reliable.
Privileged Access Audit at a Bank
Internal audit wants to determine whether production administrator access is being appropriately controlled.
Auditing a SaaS Service
A company stores sensitive customer information in a SaaS platform.
"We're SOC 2"
A critical supplier tells the security team:
"Don't worry - we're SOC 2."
The correct response is not simply:
"Great, supplier approved."
Review the Report
Each Side Passed
Internal audit finds:
On-premises IAM controls conform.
Cloud audit finds:
Cloud IAM controls conform.
Nobody audits:
the federation trust connecting them.
The Perfect Audit
Management proudly reports:
"The audit found no issues."
Further investigation reveals:
- management selected every sample;
- auditors interviewed only process owners;
- no technical evidence was examined;
- the highest-risk system was excluded from scope;
- the auditor designed the control being audited.
π CISSP Scenarios Recognise the audit concept being tested
An organisation evaluates evidence against its mandatory security policy.
Which activity?
Security audit.
A security engineer deliberately attempts a prohibited network connection to see whether a firewall blocks it.
Audit or test?
Security control test.
The result may later become audit evidence.
An auditor needs to determine what constitutes acceptable privileged access.
What should be identified?
Audit criteria.
An audit is intended to determine whether cloud administrator access satisfies organisational policy.
What does this describe?
Audit objective.
The audit covers the production cloud tenant but specifically excludes development.
Which concept?
Audit scope.
The organisation's own audit function reviews security controls.
Which audit type?
Internal / first-party audit.
A customer audits a critical supplier against contractual security requirements.
Which common audit classification?
Second-party audit.
An independent certification body audits an organisation.
Which common audit classification?
Third-party audit.
A team audits the control it designed and operates.
Primary concern?
Independence / conflict of interest.
An independent auditor has never worked with cloud systems but is assigned to audit a highly complex cloud environment.
Primary concern?
Auditor competence.
Management says access reviews always occur on time.
What should an auditor seek?
Objective supporting evidence.
The auditor reviews actual access-review records and compares them with system-account data.
Which audit principle?
Evidence-based auditing.
A security auditor focuses most effort on internet banking and less on a low-value isolated utility.
Which approach?
Risk-based auditing.
There are 100,000 transactions in the audit period and the auditor evaluates a representative subset.
Which concept?
Audit sampling.
The process owner selects only the best examples for the auditor.
Primary concern?
Sample bias / unrepresentative evidence.
The auditor watches an administrator perform the quarterly access review.
Which evidence technique?
Observation.
An auditor independently repeats a calculation used to determine access-review compliance.
Which evidence technique?
Reperformance.
An auditor relies entirely on the administrator saying a control works.
Primary weakness?
Insufficient corroborating evidence.
The evidence indicates that a mandatory security requirement is not being fulfilled.
What may this represent?
A finding / nonconformity, depending on audit methodology.
Management produces new valid evidence showing that a draft finding is incorrect.
What should the auditor do?
Evaluate the evidence objectively and revise if appropriate.
An auditor refuses to consider contrary evidence because changing the finding would "look weak."
Which principle is threatened?
Objectivity / fair presentation.
An audit concludes that a single tested application meets security requirements.
Management claims the entire organisation is therefore secure.
What is wrong?
The conclusion exceeds the audit scope.
An organisation successfully passes a compliance audit.
Does that prove no security vulnerability exists?
No.
A supplier gives the organisation an independent audit report.
What should be reviewed before relying on it?
Scope, criteria, period, auditor, exceptions and relevance.
A supplier's audit report covers a service the organisation does not actually use.
Is it sufficient assurance for the organisation's service?
Not necessarily.
The supplier's report expired two years ago.
Which concern?
Timeliness / current relevance.
A service organisation's report focuses on controls relevant to customers' internal control over financial reporting.
Which report?
SOC 1.
A service provider produces a detailed report examining controls relevant to security, availability, processing integrity, confidentiality or privacy.
Which report?
SOC 2.
A Trust Services report is intended for general use rather than containing the more detailed restricted-use SOC 2 information.
Which report?
SOC 3.
The report evaluates control design at a specified date.
Which type?
Type 1.
The report evaluates operating effectiveness during a defined period.
Which type?
Type 2.
A provider's report assumes customers configure their own MFA.
The organisation never enabled MFA.
Can the provider's audit compensate for this?
No.
The customer must satisfy its own complementary responsibility.
Cloud infrastructure controls are independently audited by the provider, while the customer audits its own cloud identities and permissions.
Which concept?
Audit aligned to shared responsibility.
On-premises and cloud environments both pass their audits, but nobody examines the federation between them.
What is missing?
Hybrid interface / trust-boundary audit coverage.
A critical supplier refuses an audit because the contract contains no audit clause.
Which lesson?
Assurance and audit rights should be addressed contractually.
An audit report lists significant security weaknesses and is emailed to hundreds of employees.
Primary concern?
Confidentiality / inappropriate distribution.
Management says an audit finding has been resolved.
What should audit consider?
Follow-up evidence verifying corrective action.
The same audit finding appears for three consecutive years.
What may this indicate?
Ineffective remediation, accountability or a systemic control weakness.
Audit analytics automatically evaluate every privileged account each week.
Which concept may this support?
Continuous or highly automated auditing.
The operations team continuously monitors privileged accounts while internal audit periodically evaluates whether that monitoring control is effective.
Which distinction?
Continuous monitoring vs audit assurance.
Audit software says 100% of users are compliant, but the source IAM database excludes several acquired subsidiaries.
Primary concern?
Audit evidence completeness and reliability.
A single low-impact account is reviewed one day late, while 200 privileged accounts were never reviewed.
Which concept helps distinguish their importance?
Risk significance / materiality.
An auditor reaches a conclusion but cannot identify which evidence supports it.
What is missing?
Audit traceability and adequate documentation.
A regulator requires an independent examination rather than a self-assessment.
Why?
Greater independence and external assurance.
An organisation focuses audits on areas with the highest potential business impact.
Which principle?
Risk-based auditing.
Audit finds that policy is documented correctly but employees do not follow it.
What does this demonstrate?
Documentation alone does not prove operational conformity.
Every required audit was completed this year, but none covered the organisation's newly launched critical AI platform.
Primary problem?
Audit programme scope may no longer reflect organisational risk.
An auditor identifies a potentially severe issue during fieldwork that could expose customers immediately.
Should the auditor always wait for the final report?
No.
Significant issues may require prompt escalation according to the audit process.
A cloud provider passes its own independent audit, but the customer's permissions allow every employee administrator access.
Which lesson?
Provider assurance does not prove customer-controlled settings are secure.
Management asks what makes an audit conclusion defensible.
Best answer?
Appropriate criteria, sufficient reliable evidence, competent auditors and objective evaluation.
Recognise the Clue Words
Compared Against Requirements
Formal assurance.
AuditWhy Audit?
Purpose.
ObjectiveWhat Is Included?
Boundary.
ScopeCompared Against What?
Expected requirement.
CriteriaWhat Proves It?
Support conclusion.
EvidenceOrganisation Audits Itself
First party.
Internal AuditCustomer Audits Supplier
Business relationship.
Second-Party AuditIndependent Certification
Outside assurance.
Third-Party AuditAuditor Built Control
Potential bias.
IndependenceAuditor Doesn't Understand Technology
Capability issue.
CompetenceReview Subset
Population evidence.
SamplingWatch Process
Evidence.
ObservationRepeat Calculation
Independent verification.
ReperformanceManagement Says It Works
Need support.
CorroborateRequirement Not Met
Audit issue.
Finding / NonconformityHighest Risk First
Focus assurance.
Risk-Based AuditFinancial Reporting Controls
Service organisation.
SOC 1Trust Services Criteria
Detailed assurance.
SOC 2Trust Services Β· General Use
Less detailed public/general report.
SOC 3As of a Date
Design.
Type 1Across a Period
Operating effectiveness.
Type 2Cloud Provider Control
Use provider evidence.
Third-Party AssuranceCustomer Cloud Configuration
Customer responsibility.
Audit YourselfOn-Prem + Cloud
Include trust connections.
Hybrid AuditFinding Fixed?
Verify.
Follow-UpSame Finding Every Year
Deeper problem.
Systemic WeaknessPassed Audit
Does not prove everything.
Scope Mattersβ οΈ Common CISSP Mistakes Security audit questions often test scope, evidence and independence
A penetration test exercises security through adversarial techniques. An audit evaluates evidence against criteria.
Assessment is broader; audit specifically focuses on systematic evaluation against defined criteria.
Audit actual evidence of implementation and operation.
Corroborate important assertions.
Auditor must also understand the relevant subject matter.
Internal auditors can provide meaningful assurance when appropriate organisational independence and objectivity exist.
Conflicts, relationships and engagement structure still matter.
Self-review threats should be considered.
Higher-risk areas generally justify greater audit attention.
Sampling creates sampling risk and requires appropriate selection.
Risk and impact matter.
An audit provides assurance against its scope and criteria.
Consider audit scope, methodology and evidence limitations.
SOC 1 concerns controls relevant to internal control over financial reporting.
It is an examination and report.
SOC 3 is intended for general use and does not provide the same detailed information as SOC 2.
Type 1 focuses on controls at a point in time.
Type 2 includes operating effectiveness over a period.
Understand shared and complementary responsibilities.
Review scope, date, service, criteria and findings.
Audit trust boundaries and interfaces too.
Assurance requirements should be addressed before dependency is established.
Reports and evidence may disclose significant security weaknesses.
Follow-up should obtain appropriate evidence.
Management remains responsible for corrective actions and risk decisions.
Monitoring is typically a management control activity; auditing is an assurance activity.
Quick Reference
| If you see... | Think... |
|---|---|
| Evidence compared against requirements | Audit |
| Why are we auditing? | Objective |
| What's included? | Scope |
| Against what? | Criteria |
| What proves it? | Evidence |
| Organisation audits itself | Internal / First Party |
| Customer audits supplier | Second Party |
| Independent certification audit | Third Party |
| Auditor evaluates own work | Independence Concern |
| Auditor lacks skills | Competence Concern |
| Subset of population | Sampling |
| Watch process operate | Observation |
| Repeat procedure independently | Reperformance |
| Requirement not satisfied | Finding / Nonconformity |
| Most important risks receive more attention | Risk-Based Audit |
| Financial reporting controls | SOC 1 |
| Trust Services detailed report | SOC 2 |
| Trust Services general-use report | SOC 3 |
| As of a date | Type 1 |
| Operating effectiveness over time | Type 2 |
| Supplier assurance report | Check Scope + Period + Exceptions |
| Provider controls | Third-Party Assurance |
| Customer cloud configuration | Customer Audit Responsibility |
| On-prem + cloud | Audit Integration |
| Auditee says finding fixed | Follow-Up Evidence |
| Same finding repeatedly | Systemic / Remediation Problem |
| Management watches controls continuously | Continuous Monitoring |
| Audit obtains assurance continuously | Continuous Auditing |
Audit Memory Aid
Audit Party Memory Aid
SOC Memory Aid
Location Memory Aid
6.5 Master Memory Aid
Criteria β Evidence β Compare β Conclude
The Security Auditor's Questions
How the Five Domain 6 Lessons Fit Together
Domain 6
Key Takeaways
CISSP 6.5 focuses on conducting or facilitating security audits.
The current CISSP outline explicitly includes internal, external, third-party and location-based audits covering on-premises, cloud and hybrid environments.
An audit systematically obtains and evaluates evidence against defined audit criteria.
The basic audit relationship is:
Criteria β Evidence β Comparison β Conclusion.
The audit objective explains why the audit is being performed.
Audit scope identifies the systems, processes, locations, organisational units and periods included.
Audit criteria define the policies, standards, laws, contractual obligations or other requirements against which evidence is evaluated.
Objective = why. Scope = what. Criteria = against what.
Assessment, testing and auditing are related but distinct.
Assessment broadly evaluates security effectiveness.
Testing exercises controls and systems.
Auditing compares objective evidence against established criteria.
Assess = effective? Test = works? Audit = conforms?
Credible audits depend on integrity, fair presentation, due professional care, confidentiality, independence and evidence-based evaluation.
Risk-based auditing directs greater assurance effort toward areas where failure could create greater organisational impact.
An audit programme coordinates multiple audits over time, while an individual audit is a specific engagement.
The audit lifecycle generally includes planning, preparation, fieldwork, evidence evaluation, reporting and follow-up.
Internal audits are performed by or on behalf of the organisation itself.
Internal auditors can provide strong assurance when appropriate independence and objectivity exist.
Internal does not mean informal.
First-party audit commonly refers to internal audit.
Second-party audit commonly refers to an interested party auditing an organisation with which it has a relationship, such as a customer auditing a supplier.
Third-party audit commonly refers to an independent auditing organisation, such as a certification body.
First = ourselves. Second = business relationship. Third = independent.
CISSP separately lists internal, external and third-party contexts, while some formal audit terminology groups second- and third-party activity under external auditing.
Auditor independence reduces the risk that conclusions are improperly influenced by responsibility for the activity being audited.
An auditor who designed or operates the control may create a self-review concern.
Independence alone is not enough.
Auditors must also have sufficient competence to understand the audit methodology, technology, business environment and applicable criteria.
Independent + competent + evidence-based = stronger assurance.
Third-party audits are particularly important where organisations depend on suppliers, cloud services, SaaS platforms and managed-service providers.
Contracts can establish audit rights, evidence requirements and assurance obligations before dependency on a supplier is created.
Existing third-party audit reports can provide useful assurance, but their scope, criteria, period, independence, exceptions and relevance should be evaluated before relying on them.
Audit report exists β audit report covers your risk.
SOC reports are commonly used to provide assurance regarding controls at service organisations.
SOC 1 concerns controls relevant to user entities' internal control over financial reporting.
SOC 2 addresses controls relevant to Trust Services Criteria involving security, availability, processing integrity, confidentiality and privacy.
SOC 3 also relates to Trust Services Criteria but provides a general-use report rather than the detailed restricted-use information associated with SOC 2.
SOC 1 = financial reporting. SOC 2 = Trust Services detailed report. SOC 3 = Trust Services general-use report.
SOC 2 should not be described as a generic "SOC 2 certification."
Type 1 reports evaluate controls at a specified point in time.
Type 2 reports include evaluation of operating effectiveness during a defined period.
Type 1 = point in time. Type 2 = over time.
Third-party reports may depend on complementary controls that the customer is responsible for implementing.
Provider assurance does not prove that customer-controlled identities, configurations or permissions are secure.
Cloud audits therefore require an understanding of shared responsibility.
Hybrid audits should evaluate not only on-premises and cloud controls but also the federation, network connectivity, APIs, data flows and other trust relationships connecting them.
Secure A + Secure B β Secure A-to-B relationship.
Audit conclusions require appropriate evidence.
Evidence may include documentation, records, logs, configurations, interviews, observations, technical tests and reperformance.
Important assertions can be corroborated using multiple evidence sources.
Management statements can provide useful information, but significant conclusions should normally be supported by appropriate objective evidence.
Audit evidence should be relevant, reliable, sufficient, current and traceable to the conclusion it supports.
Tell me β Show me β Prove it.
Sampling can be used where testing every item in a population is impractical.
Sampling introduces the possibility that the selected items do not perfectly represent the wider population.
Allowing an auditee to provide only its best examples can undermine the reliability of the sample.
Audit trails support accountability by recording who performed an action, what happened, when it happened and where it occurred.
Audit trails and other audit evidence should themselves be protected against inappropriate modification or deletion.
Audit findings connect the expected state defined by criteria with the actual state demonstrated by evidence.
Depending on the audit framework, deviations may be described using terms such as findings, exceptions, deficiencies, observations or nonconformities.
Terminology can vary; evidence and criteria are what matter.
Audit documentation and workpapers record the procedures performed, evidence obtained and basis for conclusions.
Significant findings should be traceable to the evidence supporting them.
Risk and significance should be considered rather than treating every audit deviation as equally important.
Audit reports should describe objective, scope, criteria, methodology, findings, limitations and conclusions as appropriate.
Audit scope constrains the conclusion.
Passing one security audit does not demonstrate that every system, control or threat across the organisation has been evaluated.
Compliance with audited criteria β absence of all security risk.
Management should have an opportunity to provide relevant evidence and factual clarification before findings are finalised.
Auditor independence does not mean refusing to correct a finding when better evidence demonstrates that it is wrong.
Management is normally responsible for corrective action and risk decisions arising from audit findings.
Follow-up provides evidence that agreed corrective action actually occurred.
Management says fixed β auditor has verified closure.
Repeated findings can indicate ineffective remediation, inadequate accountability or systemic control weaknesses.
Audit reports and workpapers can reveal sensitive information about vulnerabilities, control gaps, architecture and third-party weaknesses and should therefore be appropriately protected.
Continuous monitoring and continuous auditing are different concepts.
Continuous monitoring is generally a management activity that observes control and risk conditions.
Continuous auditing uses recurring or automated audit procedures to provide assurance more frequently.
Automation can increase audit coverage and frequency, but auditors still need to establish that data sources, automated logic and audit criteria are reliable.
The central CISSP principle is: define what should be true, obtain trustworthy evidence of what is actually true, evaluate the difference objectively and communicate the resulting assurance to the people who need it.
π Sources & Further Reading Current audit, security-assurance and service-organisation references
- ISC2 - CISSP Certification Exam Outline
View the current CISSP Exam Outline - ISO 19011:2026 - Guidelines for Auditing Management Systems
View ISO 19011 - ISO/IEC 27007:2020 - Guidelines for Information Security Management Systems Auditing
View ISO/IEC 27007 - NIST SP 800-53A Rev. 5 - Assessing Security and Privacy Controls
View NIST control-assessment guidance - GAO - Government Auditing Standards, 2024 Revision
View the current Yellow Book - AICPA & CIMA - SOC for Service Organizations
View AICPA SOC resources
