Section 113.121 Attestation of Findings Flashcards
Objective 5.5 Explain types and purposes of audits and assessments
Attestation
Process that involves the formal validation or confirmation provided by an enity that is used to assert the accuracy and authenricity of specific information
■ Crucial in internal and external audits to ensure the reliability and integrity of the following…
● Data
● Systems
● Processes
Attestation of Findings in Penetration Testing
Used to prove that a penetration test occurred and validate the findings
■ May be required for compliance or regulatory purposes (e.g., GLBA, HIPAA,
Sarbanes-Oxley, PCI DSS)
■ Includes a summary of findings and evidence of the security assessment
■ Evidence helps to prove that identified vulnerabilities and exploits are valid
The difference between attestation and the report
● Attestation includes evidence
● Report focuses on findings and recommended remediation
A letter of attestation may be provided to prove the occurrence of the
penetration testing, especially when required by third parties interested in
network security
Types of Attestation
Software Attestation
● Involves validating the integrity of software to ensure it hasn’t been
tampered with
Types of Attestation
Hardware Attestation
Validates the integrity of hardware components to confirm they haven’t
been tampered with
System Attestation
Validates the security posture of a system, often related to compliance
with security standards
Attestation in Audits
■ In internal audits, attestation evaluates organisational compliance, effectiveness of internal controls, and adherence to policies and procedures
■ In external audits, third-party entities provide attestation on financial statements, regulatory compliance, and operational efficiency
■ Attestation builds trust, enhances transparency, ensures accountability, and is essential for stakeholders in making informed decisions