โ† All CSC Flashcard Decks

Security Control Auditing Flashcards

6 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Security Control Auditing flashcards as text
  1. An auditor is evaluating the effectiveness of a company's security controls for a cloud-based service provider. The audit's scope is focused on controls related to security, availability, processing integrity, confidentiality, and privacy. Which of the following audit reports would be the most relevant for this evaluation?

    Answer: SOC 2 Type 2 Report

    A SOC 2 (Service Organization Control 2) report is specifically designed to provide assurance about the controls at a service organization relevant to security, availability, processing integrity, confidentiality, and privacy. A Type 2 report specifically opines on the operating effectiveness of those controls over a period of time, making it the most relevant choice for this scenario.

  2. A financial services company is preparing for its annual security control audit. The IT team wants to move from a point-in-time audit approach to a more proactive model that provides real-time insights into control effectiveness. Which of the following methodologies should they implement?

    Answer: Continuous Controls Monitoring (CCM)

    Continuous Controls Monitoring (CCM) is a technology-driven approach that continuously assesses and reports on the effectiveness of an organization's security controls in real-time or near-real-time. This proactive method moves away from traditional, periodic audits and allows for immediate identification and mitigation of risks as they arise.

  3. During a security audit based on the ISO 27001 standard, an auditor is reviewing the organization's approach to risk management. What is the primary purpose of the Annex A controls within this framework?

    Answer: To offer a comprehensive set of control objectives and controls that can be selected to mitigate identified risks.

    ISO 27001 Annex A provides a catalog of 93 security controls grouped into four categories (Organizational, People, Physical, and Technological). These are not all mandatory; rather, organizations select the applicable controls based on their own risk assessment and treatment process to mitigate identified information security risks.

  4. A U.S. federal agency is required to have its information systems audited to ensure they meet federal security and privacy mandates. The audit will assess a comprehensive catalog of technical, operational, and administrative controls. Which publication provides the foundational framework and controls for this type of audit?

    Answer: NIST Special Publication 800-53

    NIST Special Publication 800-53 provides a comprehensive catalog of security and privacy controls for all U.S. federal information systems except those related to national security. It is a mandatory framework for federal agencies to ensure compliance with the Federal Information Security Modernization Act (FISMA).

  5. Which of the following best describes the difference between an internal security audit and an external security audit?

    Answer: Internal audits are conducted by employees of the organization, while external audits are performed by an independent third party.

    The primary distinction lies in who performs the audit. Internal audits are conducted by an organization's own staff to assess adherence to internal policies and controls. External audits are conducted by independent third parties to provide an objective, unbiased assessment, often for compliance with regulations or industry standards.

  6. An auditor is tasked with performing a compliance audit. What is the primary objective of this type of security control audit?

    Answer: To evaluate and verify that the organization is adhering to specific regulatory, legal, or industry-standard requirements.

    A compliance audit's main goal is to verify that an organization adheres to specific external rules, such as laws, regulations, and industry standards (e.g., HIPAA, PCI DSS, GDPR). Unlike a vulnerability assessment or penetration test, its focus is on checking whether required controls are implemented as mandated.