MLchartDataset catalogue

audit

Term · Cybersecurity · MLC-T-CYB-000304

1. Systematic, independent and documented process for obtaining audit evidence and evaluating it objectively to determine the extent to which the audit criteria are fulfilled. Note 1: An audit can be an internal audit (first party) or an external audit (second party or third party), and it can be a combined audit (combining two or more disciplines). Note 2: An internal audit is conducted by the organization itself, or by an external party on its behalf.

2. Independent review and examination of records and activities to assess the adequacy of system controls, to ensure compliance with established policies and operational procedures.

3. Independent review and examination of records and activities to assess the adequacy of system controls and ensure compliance with established policies and operational procedures.

4. The independent examination of records and activities to ensure compliance with established controls, policy, and operational procedures and to recommend any indicated changes in controls, policy, or procedures.

Table 1. Record
IdentifierMLC-T-CYB-000304
FieldCybersecurity
ReferencesCNSSI 4009-2022 from ISO 30401:2018; NIST SP 1800-15B from NIST SP 800-12 Rev. 1; NIST SP 1800-15C from NIST SP 800-12 Rev. 1; NIST SP 800-12 Rev. 1; NIST SP 800-53 Rev. 5 from CNSSI 4009-2022; NIST SP 1800-25B from CNSSI 4009-2022; NIST SP 1800-26B from CNSSI 4009-2022; NISTIR 7316; NIST CSRC Glossary
Record as JSON
{
  "id": "MLC-T-CYB-000304",
  "term": "audit",
  "field": "Cybersecurity",
  "definition": "1. Systematic, independent and documented process for obtaining audit evidence and evaluating it objectively to determine the extent to which the audit criteria are fulfilled. Note 1: An audit can be an internal audit (first party) or an external audit (second party or third party), and it can be a combined audit (combining two or more disciplines). Note 2: An internal audit is conducted by the organization itself, or by an external party on its behalf.\n\n2. Independent review and examination of records and activities to assess the adequacy of system controls, to ensure compliance with established policies and operational procedures.\n\n3. Independent review and examination of records and activities to assess the adequacy of system controls and ensure compliance with established policies and operational procedures.\n\n4. The independent examination of records and activities to ensure compliance with established controls, policy, and operational procedures and to recommend any indicated changes in controls, policy, or procedures.",
  "references": [
    "CNSSI 4009-2022 from ISO 30401:2018",
    "NIST SP 1800-15B from NIST SP 800-12 Rev. 1; NIST SP 1800-15C from NIST SP 800-12 Rev. 1; NIST SP 800-12 Rev. 1; NIST SP 800-53 Rev. 5 from CNSSI 4009-2022",
    "NIST SP 1800-25B from CNSSI 4009-2022; NIST SP 1800-26B from CNSSI 4009-2022",
    "NISTIR 7316",
    "NIST CSRC Glossary"
  ],
  "url": "https://mlchart.com/terminology/cybersecurity/audit/"
}

Record 304 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.