Systematic, independent and documented process for obtaining audit evidence and evaluating it objectively to determine the extent to which the audit criteria are fulfilled. Note 1: An audit can be an internal audit (first party) or an external audit (second party or third party), and it can be a combined audit (combining two or more disciplines). Note 2: An internal audit is conducted by the organization itself, or by an external party on its behalf.
Sources:
CNSSI 4009-2022
from
ISO 30401:2018
Independent review and examination of records and activities to assess the adequacy of system controls, to ensure compliance with established policies and operational procedures.
Sources:
NIST SP 1800-15B
under Audit
from
NIST SP 800-12 Rev. 1
NIST SP 1800-15C
under Audit
from
NIST SP 800-12 Rev. 1
NIST SP 800-12 Rev. 1
under Audit
from
CNSSI 4009
NIST SP 800-53 Rev. 5
from
CNSSI 4009-2022
Independent review and examination of records and activities to assess the adequacy of system controls and ensure compliance with established policies and operational procedures.
Sources:
NIST SP 1800-25B
under Audit
from
CNSSI 4009-2022
NIST SP 1800-26B
under Audit
from
CNSSI 4009-2022
The independent examination of records and activities to ensure compliance with established controls, policy, and operational procedures and to recommend any indicated changes in controls, policy, or procedures.
Sources:
NISTIR 7316
under Audit