security audit
/sɪˈkjʊə.rə.ti ˈɔː.dɪt/noun
A security audit is a structured examination of a digital system's security. The auditor assesses technical measures and processes against agreed requirements and records findings.
Before launch, the organization commissioned an independent security audit of the customer portal.
In a security audit, an auditor examines an application's security, underlying infrastructure and associated processes. Areas may include Glossary · In briefauthenticationAuthentication is the process by which a system verifies the claimed identity of a user, device or application.Read more, access permissions, configuration, Glossary · In briefencryptionEncryption converts readable data into encrypted data using an algorithm and a cryptographic key. Only the correct key can make the data readable again.Read more, Glossary · In briefloggingLogging records events while software is running. These records help developers follow a system's behaviour and investigate problems.Read more and how security updates are applied.
What is examined?
The client and auditor agree on a Glossary · In briefscopeScope defines the boundaries of a project or assignment: which goals, activities and results are included and which are excluded.Read more and assessment framework in advance. These identify the systems, environments and processes to examine and the requirements used to assess them. The auditor then gathers evidence by reviewing settings and documentation, interviewing staff or performing technical checks.
The report describes identified risks, usually with an assessment of severity and potential consequences. It often includes recommendations. Developers and administrators can use it to prioritize measures. A follow-up assessment can check whether the findings have been resolved.
Security audit or penetration test?
A penetration test mainly searches actively for technically exploitable vulnerabilities. A security audit can be broader, also examining architecture, configuration, access management and procedures. A penetration test can form part of an audit.
A security audit does not prove a system will remain secure. Software, threats and configurations change. Regular checks and follow-up on findings are therefore part of ongoing security management.