An organization requires an independent, formal evaluation performed by an accredited third-party organization to verify that its information security controls conform to established compliance standards. Which of the following processes best satisfies this requirement?
- External security auditAnswer
- BInternal compliance self-assessment
- CAutomated vulnerability assessment
- DThird-party penetration test
Answer
The external security audit provides an independent, accredited third-party evaluation of security controls against formal compliance standards.
An external security audit involves an independent, qualified third party evaluating an enterprise's control environment to confirm compliance with official standards, regulations, or frameworks.
Step-by-Step Solution
Key Concept
Independent Third-Party Security Audits