5.5 — Audits and Assessments

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/20

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 8:41 PM on 8/30/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

21 Terms

1
New cards
Internal audit
Audit performed by or for the organization to evaluate internal controls, compliance, or processes.
2
New cards
Compliance audit
Audit that checks whether activities and controls meet specified laws, regulations, policies, or standards.
3
New cards
Audit committee
Governance group that oversees audit activities, financial reporting, and related control matters.
4
New cards
Self-assessment
Organization's own evaluation of its security, controls, or compliance posture.
5
New cards
External audit
Audit performed by an independent outside organization.
6
New cards
Regulatory audit
Audit or examination performed by or on behalf of a regulatory authority.
7
New cards
Examination
Formal review or inspection used to determine compliance, condition, or effectiveness.
8
New cards
Independent third-party audit
Audit performed by an external party with sufficient independence from the organization being audited.
9
New cards
Physical penetration testing
Authorized testing that attempts to bypass or defeat physical security controls.
10
New cards
Offensive penetration testing
Authorized security testing focused on actively attempting to exploit weaknesses.
11
New cards
Defensive penetration testing
Testing focused on evaluating the effectiveness of defensive controls against simulated attacks.
12
New cards
Integrated penetration testing
Testing that combines multiple attack paths or domains, such as physical, network, and application testing.
13
New cards
Known environment
Penetration test in which the tester has substantial information about the target environment.
14
New cards
Partially known environment
Penetration test in which the tester receives limited information about the target.
15
New cards
Unknown environment
Penetration test in which the tester receives little or no information about the target beforehand.
16
New cards
Reconnaissance
Information gathering performed before or during a penetration test.
17
New cards
Passive reconnaissance
Collecting information without directly interacting with the target systems.
18
New cards
Active reconnaissance
Collecting information by directly interacting with the target systems or network.
19
New cards
Audit
Formal examination of systems, processes, controls, or records against defined requirements.
20
New cards
Assessment
Evaluation used to determine the effectiveness, condition, risk, or compliance of a system or control.
21
New cards
External assessment
Evaluation performed by an outside party to assess security controls, processes, or risks.