From the course: CompTIA CySA+ (CS0-002) Cert Prep: 7 Compliance and Assessment

Unlock the full course today

Join today to access over 22,600 courses taught by industry experts or purchase this course individually.

Audits and assessments

Audits and assessments

From the course: CompTIA CySA+ (CS0-002) Cert Prep: 7 Compliance and Assessment

Start my 1-month free trial

Audits and assessments

- [Instructor] Audits and assessments provide organizations with the opportunity to evaluate their security controls to ensure that they're working properly and that they're effectively protecting the confidentiality, integrity, and availability of information in systems. Audits and assessments as similar in purpose and function. Both involve evaluating security controls, reporting on their effectiveness and making recommendations for improvements. The main difference lies in the purpose of the review. Assessments are generally performed by, or requested by, an organization's IT staff. Audits are generally performed at the request of someone else such as a regulator, executive, or board of directors. No matter what type of audit or assessment is taking place, the engagement should always begin with a planning process that clearly outlines the scope of the engagement, the timeline for completion, and the expected deliverables.…

Contents