Security Assessment and Testing

John Warsinkse · 2019

This chapter focuses on t importance of security assessments, risk assessments, and security audits. A security audit compares its results against a standard to determine whether the standard is being met. Third-party audits are often required for legal or contractual compliance, but internal auditors are also used by many organizations to provide oversight over their own efforts. Security assessments are used to determine an organization's security posture. This means that assessors use standards as well as their own knowledge and experience to assess the strength and effectiveness of their security posture. Thus, all security audits are a form of security assessment, but not all security assessments are audits. Risk assessments provide a view of the risks that an organization faces. Many risk assessments categorize risks by probability and impact and include details of findings and potential controls. Once an organization has completed an assessment or audit, it must prioritize the actions it will take in response.

Read the paper · More papers on PaperTik