ISC2 Certified in Cybersecurity (CC)Security OperationsMedium

A financial institution is implementing a new system for processing customer transactions. Before going live, they want to ensure that the system's security controls are effective and meet regulatory requirements. Which type of assessment focuses on evaluating the design and implementation of these controls against established criteria?

  1. ARisk assessment
  2. BSecurity audit
  3. CVulnerability scan
  4. DPenetration test
Show answer & explanation

Correct answer: B. Security audit

A security audit systematically evaluates an organization's information systems against a set of established criteria, such as policies, regulations, or industry standards, to determine compliance and control effectiveness. This aligns with ensuring security controls meet regulatory requirements.

Why the other options are wrong

  • A. A risk assessment identifies and evaluates potential threats and vulnerabilities, and their impact, but doesn't primarily focus on evaluating control implementation against requirements.
  • C. A vulnerability scan identifies known weaknesses in systems and applications, but does not typically evaluate the broader design or compliance of security controls.
  • D. A penetration test actively exploits vulnerabilities to simulate an attack, focusing on discoverable weaknesses, not necessarily overall control design adherence.

Security Audit

A systematic evaluation of an organization's information systems to determine compliance with policies, regulations, and industry standards.

  • Assesses control effectiveness and regulatory adherence.
  • Often performed by independent third parties.
  • Results in recommendations for improvement.

Memory trick: Audits check compliance, scans find weak spots, pen tests break in.

More Security Operations questions