A systematic evaluation of an organization's information security controls, policies, and procedures to assess their effectiveness and identify gaps. Audits can be internal or conducted by independent third parties for compliance certification.
Related Terms
Compliance
complianceThe practice of adhering to laws, regulations, industry standards, and internal policies related to information security...
ISO 27001
complianceAn international standard for information security management systems (ISMS). ISO 27001 provides a systematic approach t...
SOC 2
complianceA compliance framework developed by AICPA that evaluates an organization's controls related to security, availability, p...