A hospital network contracts a third-party security firm to perform a systematic evaluation of its electronic health records (EHR) infrastructure. The assessors conduct staff interviews, review policy documentation, and inspect access log configurations against established regulatory safeguards to verify compliance. The assessment team does not execute exploit scripts or perform automated vulnerability scanning against live endpoints. Which of the following assessment types is being performed?
- Security auditCevap
- BPenetration test
- CVulnerability assessment
- DAttestation of compliance
Cevap
Security audit
A security audit is a structured examination designed to evaluate how well an organization adheres to established security policies, baseline standards, or regulatory frameworks. It uses non-disruptive methods—such as reviewing documentation, inspecting system configurations, and interviewing staff—to gather objective evidence of control compliance.
Adım Adım Çözüm
Anahtar Kavram
Security Audits vs. Assessments