DFIELDSOLUTIONS

Security

GlossarySecurity audit

A systematic review of a system against a standard or a set of criteria, aiming for coverage rather than for a way in.

An audit and a penetration test answer different questions and are routinely confused. The audit asks whether the controls that should exist do exist, across the whole surface, including the parts an attacker would never bother with. The test asks whether somebody can get in, and stops when they do.

Which one you want depends on the question you are actually asking. "Can we be broken into" is a test. "Are we sound, and can we show somebody that we are" is an audit. Compliance and due diligence generally want the second, and the two are complementary rather than substitutes — an audit with no testing behind it is a review of intentions.

Related terms

The bench this belongs to

Cybersecurity

Purple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.

All termsStart a conversationMarkdown version

DField Bt. · Dunakeszi · dezso@dfieldsolutions.com
5.0
“From LinkedIn DM to live site. Two tiny tweaks, then shipped.”Michael J Ringer · Vilya ProtectionFounder · Spain