The security assessment and testing domain focuses on *identifying and mitigating risks, threats, and vulnerabilities*. Security assessments help organisations determine whether their internal systems are secure or at risk. Organisations might employ penetration testers, often referred to as “pen testers,” to find vulnerabilities that could be exploited by a threat actor. This domain suggests that organisations *conduct security control testing*, as well as *collect and analyse data*. Additionally, it emphasises the importance of *conducting [[Security Audits]]* to monitor for and reduce the probability of a data breach. To contribute to these types of tasks, cybersecurity professionals may be tasked with *auditing user permissions* to validate that users have the *correct levels of access* to internal systems.