Security audits use many of the same techniques followed during security assessments but must be *performed by independent auditors*. *Assessment and testing* results are meant for **internal use** only and are designed to evaluate controls with an eye toward finding potential improvements. *Audits*, on the other hand, are formal examinations performed with the purpose of **demonstrating** the effectiveness of controls **to a third party**. The staff who design, implement, and monitor controls for an organization have an inherent conflict of interest when evaluating the effectiveness of those controls. Auditors write reports that are quite similar to security assessment reports, but those reports are intended for different audiences that may include an organisation's board of directors, government regulators, and other third parties. One of the *primary outcomes* of an audit is an **attestation** by the auditor. This is a formal statement that the auditors have reviewed the controls and found that they are both adequate to *meet the control objectives* and working properly. ### Internal Audits Internal audits are performed by an organisation's *internal audit staff* and are typically intended for internal audiences. The internal audit staff performing these audits normally have a *reporting line* that is completely independent of the functions they evaluate. In many organisations, the chief audit executive reports directly to the president, chief executive officer (**CEO**), or similar role. The chief audit executive (**CAE**) may also have reporting responsibility directly to the organisation's governing board and/or the audit committee of that board. Internal audits may be conducted for a variety of reasons. Often, management or the board would like to obtain *reassurance* that the organization is meeting its *compliance obligations*. In addition, the internal audit team may lead a series of self-assessments designed to identify control gaps in advance of a more formal external audit. ### External Audits External audits are performed by an *outside auditing firm* who serves as an independent third party. These audits have a *high degree of external validity* because the auditors performing the assessment theoretically have no conflict of interest with the organization itself. There are thousands of firms who perform external audits, but most people place the highest credibility with the so-called **Big Four audit firms**: * Ernst & Young * Deloitte * PricewaterhouseCoopers (PwC) * KPMG Audits performed by these firms are generally considered acceptable by most investors and governing body members. ### Independent Third-Party Audits Independent third-party audits are conducted by, or on behalf of, another organisation. For example, a regulatory body might have the authority to initiate an audit of a regulated firm under contract or law. In the case of an independent third-party audit, the organisations initiating the audit generally selects the auditors and designs the scope of the audit. > [!important] External Vs. Independent > Independent third-party audits are a subcategory of external audits. The only difference is who is requesting the audit. For *external* audit, the request comes **from the organisation** or it's governing body. For an *independent* third-party audit, the request comes from a **regulator, customer, or other outside entity**. Organisations that provide services to other organisations are frequently asked to participate in independent third-party audits. This can be quite a *burden on the audited organization* if they have a large number of clients. The *American Institute of Certified Public Accountants* (**AICPA**) released a standard designed to alleviate this burden. The **Statement on Standards for Attestation Engagements document 18** ([[SSAE 18]]), titled Reporting on Controls, provides a common standard to be used by auditors performing assessments of service organisations with the intent of allowing the organization to conduct an external assessment instead of multiple third-party assessments and then sharing the resulting report with customers and potential customers. SSAE 18 engagements are commonly referred to as *service organization controls* (SOC) audits. ### [[Auditing Standards]]