An organization is preparing its annual compliance roadmap and needs to explain the purpose of external third-party security audits to executive leadership. Which of the following statements correctly describe key characteristics of an external third-party security audit? (Select TWO.)
- It provides independent, objective assurance of security controls to external stakeholders and regulators.Cevap
- It evaluates operational and technical controls against an established compliance standard or audit framework.Cevap
- CIt acts as an automated detective control designed to intercept and block malicious network traffic in real time.
- DIt serves as a direct technical mitigation that automatically remediates host software vulnerabilities found during testing.
Cevap
The statements correctly describing an external third-party security audit are that it provides independent, objective assurance of security controls to external stakeholders and regulators, and it evaluates operational and technical controls against an established compliance standard or audit framework.
External third-party security audits are defined by independent evaluations conducted by external assessors to provide objective verification to stakeholders and regulators. They evaluate an organization's existing controls against established standards or compliance frameworks.
Adım Adım Çözüm
Anahtar Kavram
Key Characteristics of External Security Audits
Tahmini Süre:1m 0s