A **security audit** is a review of an organisation's security controls, policies, and procedures against a set of expectations. Audits are *independent reviews* that evaluate whether an organization is meeting internal and external criteria. Internal criteria include outlined policies, procedures, and best practices. External criteria include regulatory compliance, laws, and federal regulations. Additionally, a security audit can be used to assess an organisation's established [[Security Controls]]. Audits help ensure that security checks are made (i.e., daily monitoring of security information and event management dashboards), to identify [[Threats]], [[Risks]], and [[Vulnerabilities]]. This helps maintain an organisation’s security posture. And, if there are security issues, a remediation process must be in place. ### Goals and objectives of an audit The goal of an audit is to ensure an organisation's *information technology (IT) practices are meeting industry and organisational standards*. The objective is to identify and address areas of remediation and growth. Audits provide direction and clarity by identifying what the current failures are and developing a plan to correct them. Security audits must be performed to safeguard data and avoid penalties and fines from governmental agencies. The frequency of audits is dependent on local laws and federal compliance regulations. ### Factors that affect audits Factors that determine the types of audits an organization implements include: - Industry type - Organisation size - Ties to the applicable government regulations - A business’s geographical location - A business decision to adhere to a specific regulatory compliance ### The role of frameworks and controls in audits Along with compliance, it’s important to mention the role of **frameworks and controls** in security audits. Frameworks such as the National Institute of Standards and Technology Cybersecurity Framework ([[Cybersecurity Framework|NIST CIF]]) and the international standard for information security (ISO 27000) series are designed to help organisations prepare for regulatory compliance security audits. By adhering to these and other relevant frameworks, organisations can save time when conducting external and internal audits. Additionally, frameworks, when used alongside controls, can support organisations’ ability to align with regulatory compliance requirements and standards. There are three main categories of [[Security Controls|controls]] to review during an audit, which are administrative and/or managerial, technical, and physical controls. ### Common elements of internal audit - Establish the scope and goals - Conducting a risk assessment - Completing a controls assessment - Assessing compliance - Communicating results