课程: ISC2 Certified Information Systems Security Professional (CISSP) (2024) Cert Prep

免费学习该课程!

今天就开通帐号,24,600 门业界名师课程任您挑!

Audits and assessments

Audits and assessments

- [Instructor] Audits and assessments provide organizations with the opportunity to evaluate their security controls to ensure that they're functioning properly and effectively protecting the confidentiality, integrity, and availability of information and systems. Audits and assessments are similar in purpose and function. Both involve evaluating security controls, reporting on their effectiveness, and making recommendations for improvement. The main difference is in the purpose of the review. Assessments are generally performed by or requested by an organization's IT staff. Audits are formal examinations generally performed at the request of someone else, such as a regulator, executive, or board of directors. When an organization undergoes an audit, the auditors follow a formal audit standard and perform planned tests that are designed to determine how well the organization complies with the standard. No matter what type of audit or assessment is taking place, the engagement should…

内容