Systematic examination of processes, controls, and records to verify compliance and effectiveness.
An audit is a systematic examination of an organisation's processes, controls, and records to verify compliance with standards, regulations, or policies. Internal audits are conducted by the organisation itself; external audits are performed by independent third parties. Audits assess whether controls exist, are properly designed, and operate effectively. Audit findings identify gaps requiring remediation. Regular audits are required by most compliance frameworks and demonstrate ongoing compliance to stakeholders.
Why It Matters
The DSC Perspective:
Audits verify your compliance claims. Prepare by maintaining documentation, evidence of control operation, and records of security activities. Audit findings should drive genuine improvement, not just minimal fixes.
