CISSP GLOSSARY · SECURITY OPERATIONS

Security audit

A formal, evidence-based evaluation of controls against a defined standard, performed by internal, external, or third-party auditors whose independence determines its credibility.

A security audit is a formal, evidence-based evaluation of an organisation’s controls against a defined standard, such as ISO 27001, PCI DSS, or the organisation’s own security policy. Auditors examine whether controls exist, operate as documented, and produce the records that prove it. The result is a formal report of conformity and findings, delivered to the party that commissioned the audit rather than to the teams being audited.

Who performs the audit determines who can rely on it. Internal audits, run by the organisation’s own audit function, serve management and the board but carry limited independence. External audits are performed by an outside firm and serve stakeholders who need an unbiased opinion, such as regulators, customers, and shareholders. Third-party audits are conducted on behalf of another organisation, typically a customer or regulator examining a supplier. Across all three, independence is the governing principle: no auditor should ever evaluate work they performed or manage themselves.

Exam relevance: if a scenario asks who an audit serves or questions the objectivity of findings, the answer turns on auditor independence, and external beats internal whenever outsiders must rely on the result. Contrast penetration testing, a technical exercise proving exploitability, and a security assessment, a broad internal review that produces advisory recommendations rather than a formal attestation. If the deliverable is a formal opinion measured against a named standard, the answer is audit.