Question

Difficulty: MediumSecurity Audits, Assessments, and Attestations

A hospital network contracts a third-party security firm to perform a systematic evaluation of its electronic health records (EHR) infrastructure. The assessors conduct staff interviews, review policy documentation, and inspect access log configurations against established regulatory safeguards to verify compliance. The assessment team does not execute exploit scripts or perform automated vulnerability scanning against live endpoints. Which of the following assessment types is being performed?

  1. Security auditAnswer
  2. B
    Penetration test
  3. C
    Vulnerability assessment
  4. D
    Attestation of compliance

Answer

Security audit
A security audit is a structured examination designed to evaluate how well an organization adheres to established security policies, baseline standards, or regulatory frameworks. It uses non-disruptive methods—such as reviewing documentation, inspecting system configurations, and interviewing staff—to gather objective evidence of control compliance.

Step-by-Step Solution

1
Analyze the evaluation methodology described in the scenario.
The assessment relies on interviewing personnel, examining policy documentation, and inspecting log configurations against compliance standards without active scanning or exploitation.
Understanding the nature of data gathering (passive review vs. active scanning/exploitation) determines the evaluation category.
2
Map the methodology to standardized security assessment definitions.
Systematic verification of controls against an established standard using documentation, interviews, and configuration checks defines a security audit.
Audits focus on evaluating adherence to governance policies and regulatory frameworks through qualitative and quantitative evidence.

Key Concept

Security Audits vs. Assessments
Rate this question