Section 13.117 Performing an External Assessment Flashcards
Objective 5.5 Explain types and purposes of audits and assessments
External Assessment
Part of maintaining a robust security posture and ensuring compliance
Checklist and procedures vary depending on Governance, Risk and Compliane practices
EXAMPLE: Sample checklist used for a HIPAA external assessment
HIPPA Audit Checklist
Purpose is to validate compliance with specific regulations and minimise cybersecurity risks
Preparing for a HIPAA External Assessment
■ Examiners provide a checklist of questions that organizations must answer
■ Questions are answered as either “yes” or “no”
■ Evidence files, such as documents or links, must be provided to demonstrate
compliance
Sample Checklist
■ Questions cover various aspects like general information, policies, procedures, and employee training
■ Organizations must provide evidence files as proof of compliance
■ External assessments aim to provide a quick overview of the organization’s
current risk posture