Security testing finds weaknesses before attackers do and gives evidence about whether controls actually work. An auditor may perform some tests directly, rely on tests performed by others such as an internal security team or an external firm, or review the organization's own testing program. In every case, the questions are whether testing is risk-based, performed by qualified and suitably independent people, properly authorized, and followed by timely remediation.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.