CISSP · Question #1510
Which of the following should exist in order to perform a security audit?
The correct answer is A. Industry framework to audit against. A security audit requires a defined framework or standard to measure against, providing the criteria and benchmarks that determine compliance or deficiencies.
Question
Options
- AIndustry framework to audit against
- BExternal (third-party) auditor
- CInternal certified auditor
- DNeutrality of the auditor
How the community answered
(51 responses)- A90% (46)
- B6% (3)
- C2% (1)
- D2% (1)
Why each option
A security audit requires a defined framework or standard to measure against, providing the criteria and benchmarks that determine compliance or deficiencies.
An industry framework (such as ISO 27001, NIST, or CIS Controls) is a prerequisite for a security audit because it defines the specific controls, benchmarks, and criteria against which the organization's security posture is evaluated. Without a framework, there is no objective baseline to measure compliance or identify gaps. The framework provides the structured methodology and scope that makes the audit valid and reproducible.
While external auditors can add objectivity, they are not a strict requirement - many valid security audits are conducted internally, making a third-party auditor optional rather than mandatory.
An internal certified auditor is one valid option for conducting an audit, but certification and internal status are not universally required prerequisites; what matters is having a standard to audit against, not who performs the audit.
Auditor neutrality is a best practice that improves audit quality and credibility, but it is not a foundational requirement that must exist before an audit can be performed - an audit can still occur without guaranteed neutrality.
Concept tested: Prerequisites and requirements for conducting security audits
Source: https://www.nist.gov/cyberframework
Topics
Community Discussion
No community discussion yet for this question.