nerdexam
(ISC)2

CISSP · Question #1510

Which of the following should exist in order to perform a security audit?

The correct answer is A. Industry framework to audit against. A security audit requires a defined framework or standard to measure against, providing the criteria and benchmarks that determine compliance or deficiencies.

Submitted by tom_us· Mar 5, 2026Security Assessment and Testing

Question

Which of the following should exist in order to perform a security audit?

Options

  • AIndustry framework to audit against
  • BExternal (third-party) auditor
  • CInternal certified auditor
  • DNeutrality of the auditor

How the community answered

(51 responses)
  • A
    90% (46)
  • B
    6% (3)
  • C
    2% (1)
  • D
    2% (1)

Why each option

A security audit requires a defined framework or standard to measure against, providing the criteria and benchmarks that determine compliance or deficiencies.

AIndustry framework to audit againstCorrect

An industry framework (such as ISO 27001, NIST, or CIS Controls) is a prerequisite for a security audit because it defines the specific controls, benchmarks, and criteria against which the organization's security posture is evaluated. Without a framework, there is no objective baseline to measure compliance or identify gaps. The framework provides the structured methodology and scope that makes the audit valid and reproducible.

BExternal (third-party) auditor

While external auditors can add objectivity, they are not a strict requirement - many valid security audits are conducted internally, making a third-party auditor optional rather than mandatory.

CInternal certified auditor

An internal certified auditor is one valid option for conducting an audit, but certification and internal status are not universally required prerequisites; what matters is having a standard to audit against, not who performs the audit.

DNeutrality of the auditor

Auditor neutrality is a best practice that improves audit quality and credibility, but it is not a foundational requirement that must exist before an audit can be performed - an audit can still occur without guaranteed neutrality.

Concept tested: Prerequisites and requirements for conducting security audits

Source: https://www.nist.gov/cyberframework

Topics

#security audit#audit framework#compliance

Community Discussion

No community discussion yet for this question.

Full CISSP Practice