Performing an Audit or Security Test
摘要
Compliance means that the organization and its actors adhere to applicable regulation and organizational policy and standards. The main purposes of audit are to measure conformance to policy, standards and regulation, and to evaluate organizational risk [4]. Auditors are professional evaluators who test for compliance and/or that certain objectives are met. Therefore, understanding audit techniques professionalize testing, whether it is done for test or audit purposes. This chapter includes two major sections: the first section is on internal testing or informal audit, which describes the stages of an audit, and the second emphasizing external or professional audit, which discusses sampling methods, audit resources, evidence and different types of audits.