ISC2 Certified in Cybersecurity (CC)Security OperationsMedium
An organization is preparing for a security audit. As part of this preparation, they are compiling documentation of their security policies, incident response plans, and records of past security assessments. The auditor will review these documents to determine if the organization's security posture aligns with established standards and regulations. What is the primary objective of this security audit?
- ATo identify zero-day vulnerabilities in critical systems.
- BTo simulate an attack and identify exploitable weaknesses.
- CTo assess compliance with security policies and regulatory requirements.
- DTo provide real-time alerts for ongoing security incidents.
Show answer & explanationAnswer & explanation
Correct answer: C. To assess compliance with security policies and regulatory requirements.
Security audits primarily focus on evaluating an organization's adherence to established policies, procedures, and regulatory requirements, rather than active vulnerability discovery or incident detection.
Why the other options are wrong
- A. Identifying zero-day vulnerabilities is typically part of advanced penetration testing or threat research, not a standard audit.
- B. Simulating an attack is penetration testing, which is distinct from a compliance-focused security audit.
- D. Providing real-time alerts is a function of security monitoring systems, not a security audit.
Security Audit
A systematic evaluation of an organization's security posture, policies, and controls to determine their effectiveness and compliance with established standards, regulations, and internal policies.
- Focuses on compliance and effectiveness of controls
- Often involves document review, interviews, and control testing
- Differs from vulnerability scanning or penetration testing
Memory trick: Assessments check security in different ways.