Section 13.113 Audits and Assessments Flashcards

Objective 5.5: Explain types and purposes of audits and assessments

1
Q

Audits

A

Systematic evaluations of an organization’s information systems, applications, and security controls to assetrain their efficiency and effectivness

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Internal Audits

A

Conducted by the organization’s own team

● Internal Audit Example
○ Review of data protection policies
○ Check policy relevance and compliance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

External Audits

A

Performed by third-party entities

External Audit Example
○ Evaluation of e-commerce PCI DSS compliance
○ Assess network security, data encryption, and access controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Significance of Audits

A

○ Identifying Gaps
■ Security policies, procedures, and controls

○ Ensuring Compliance
■ GDPR, HIPAA, PCI DSS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Assessments

A

Performing a detailed analysis of an organisations security systems to identify vulnerabilities and risks

Performed before implementing new systems or significant changes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

3 Risk Assessment catagories

A

● Risk Assessments
● Vulnerability Assessments
● Threat Assessments

How well did you know this?
1
Not at all
2
3
4
5
Perfectly