CISSP - Security Assessment and Testing (12% of the exam) - Section 6.5

Conduct or facilitate security audits that are internal, external, and third-party in scope.

Conduct or facilitate security audits across internal, external, and third-party scopes by coordinating evidence collection, interviewing control owners, and ensuring auditor independence. Recognise when the organisation's role shifts from auditee to audit sponsor, and adjust facilitation responsibilities accordingly.

internal auditexternal auditthird-party auditaudit facilitation

Practice question for this objective

Free sampleSecurity Assessment and Testingmedium

An external audit firm has been engaged to assess a manufacturer's identity and access management controls. On day one the lead auditor sends the security manager a long list of evidence requests, several of which would require production system changes, and asks for direct read access to the IAM database. The security manager wants the audit to succeed but is also accountable for production stability and data confidentiality. What should the security manager do FIRST?

  • AGrant the auditor a temporary privileged account on the IAM database so the evidence requests can be fulfilled without delay.
  • BRefer every request to legal so that the audit can only continue once a revised statement of work is signed by both parties.
  • CDecline the evidence requests until the auditor narrows the list, on the basis that the volume suggests scope creep beyond what management agreed.
  • DReview the requests against the agreed audit scope and evidence protocol, then work with the auditor to provide equivalent evidence through controlled extracts and walkthroughs rather than direct production access. Correct
Facilitate an external audit by providing controlled evidence that satisfies the auditor without weakening production security or independence. Audit facilitation is a balancing act between cooperating with the auditor and preserving security controls such as least privilege, change management, and segregation of duties. The recommended approach is to verify requests against the agreed scope, then offer evidence through controlled means such as extracts, reports, or supervised walkthroughs, which keeps the auditor independent of operations while still satisfying evidentiary needs.

Why A is wrong: Issuing privileged production access on demand bypasses change control and least privilege, and it also compromises auditor independence by giving them operator capabilities; speed of evidence collection is not a justification for weakening access controls.

Why B is wrong: Legal review of scope changes is reasonable, but routing routine evidence requests through contract renegotiation stalls the audit and is disproportionate when the existing engagement letter already covers evidence access through agreed channels.

Why C is wrong: Outright refusal damages the audit relationship and may itself be reported as a scope limitation. A breadth of requests is normal early in fieldwork; the right response is to manage how evidence is provided, not to block it.

Why D is correct: Facilitating the audit means honouring the engagement while protecting production and confidentiality. Comparing requests to scope, then supplying sanitised extracts, screen-shares, or read-only reporting environments, gives the auditor sufficient evidence without granting standing production access, which is the manager-led risk-balanced response.

See more CISSP practice questions, answers explained.

Exam traps in Security Assessment and Testing

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISSP bank for this domain.

  • Drafting the audit opinion alongside the lead auditor so that final wording reflects management's view of residual risk before issuance to the audit committee.

    Why it is wrong: Drafting the opinion would compromise the auditor's independence and is explicitly outside the auditee's remit. Facilitation supports the audit process; it does not author the auditor's conclusions, which must be formed independently of management.

  • Replace internal audit reviews with an external financial audit and use the resulting opinion to answer customer assurance requests.

    Why it is wrong: An external financial audit attests to financial statements, not to the security commitments of a hosted platform, so it will not satisfy customer assurance requests; collapsing internal reviews also removes ongoing management oversight of controls between audits.

  • An internal audit, because the SaaS provider is the audited party and must commission and staff the review using independent personnel from within the company.

    Why it is wrong: Internal audits are commissioned and staffed by the audited organisation's own assurance function reporting to its audit committee, not by an outside customer. The reviewer here is engaged and directed by an external party, so the engagement does not meet that definition even though the auditee provides the systems.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.