ISC2 Certified in Cybersecurity (CC)Security PrinciplesEasy
An organization is implementing a new access control system. Before the system goes live, they want to ensure that all security controls are functioning as intended and that the system adheres to established security policies and standards. Which process involves systematically examining the system's security posture against predefined criteria?
- ASecurity Audit
- BRisk Appetite Definition
- CSecurity Awareness Training
- DDisaster Recovery Planning
Show answer & explanationAnswer & explanation
Correct answer: A. Security Audit
A security audit is a systematic evaluation of the security of a company's information system by measuring how well it conforms to a set of established criteria. This process helps identify weaknesses and verify compliance.
Why the other options are wrong
- B. Risk Appetite Definition determines acceptable risk levels, not control effectiveness.
- C. Security Awareness Training educates users, but doesn't check system controls.
- D. Disaster Recovery Planning focuses on restoring operations after a disruption, not initial control validation.
Security Audit
A systematic evaluation of the security of a company's information system by measuring how well it conforms to a set of established criteria.
- Identifies vulnerabilities and policy violations.
- Can be internal or external.
- Verifies compliance with standards and regulations.
Memory trick: Audits inspect, training instructs, planning protects, appetite accepts.