CISSP - Security Assessment and Testing - Section 6.5

Conduct or facilitate security audits that are internal, external, and third-party in scope.

Conduct or facilitate security audits across internal, external, and third-party scopes by coordinating evidence collection, interviewing control owners, and ensuring auditor independence. Recognise when the organisation's role shifts from auditee to audit sponsor, and adjust facilitation responsibilities accordingly.

internal auditexternal auditthird-party auditaudit facilitation

Practice question for this objective

Free sampleSecurity Assessment and Testingmedium

An external audit firm has been engaged to assess a manufacturer's identity and access management controls. On day one the lead auditor sends the security manager a long list of evidence requests, several of which would require production system changes, and asks for direct read access to the IAM database. The security manager wants the audit to succeed but is also accountable for production stability and data confidentiality. What should the security manager do FIRST?

  • AGrant the auditor a temporary privileged account on the IAM database so the evidence requests can be fulfilled without delay.
  • BRefer every request to legal so that the audit can only continue once a revised statement of work is signed by both parties.
  • CDecline the evidence requests until the auditor narrows the list, on the basis that the volume suggests scope creep beyond what management agreed.
  • DReview the requests against the agreed audit scope and evidence protocol, then work with the auditor to provide equivalent evidence through controlled extracts and walkthroughs rather than direct production access. Correct
Facilitate an external audit by providing controlled evidence that satisfies the auditor without weakening production security or independence. Audit facilitation is a balancing act between cooperating with the auditor and preserving security controls such as least privilege, change management, and segregation of duties. The recommended approach is to verify requests against the agreed scope, then offer evidence through controlled means such as extracts, reports, or supervised walkthroughs, which keeps the auditor independent of operations while still satisfying evidentiary needs.

Why A is wrong: Issuing privileged production access on demand bypasses change control and least privilege, and it also compromises auditor independence by giving them operator capabilities; speed of evidence collection is not a justification for weakening access controls.

Why B is wrong: Legal review of scope changes is reasonable, but routing routine evidence requests through contract renegotiation stalls the audit and is disproportionate when the existing engagement letter already covers evidence access through agreed channels.

Why C is wrong: Outright refusal damages the audit relationship and may itself be reported as a scope limitation. A breadth of requests is normal early in fieldwork; the right response is to manage how evidence is provided, not to block it.

Why D is correct: Facilitating the audit means honouring the engagement while protecting production and confidentiality. Comparing requests to scope, then supplying sanitised extracts, screen-shares, or read-only reporting environments, gives the auditor sufficient evidence without granting standing production access, which is the manager-led risk-balanced response.

See more CISSP practice questions with worked answers.

More in this domain

Back to all Security Assessment and Testing objectives, or the CISSP cert hub.

Examworthy is not affiliated with or endorsed by (ISC)2. Original, blueprint-aligned practice material only.