Terminology Index
1801 terms
Showing 97-128 of 1801 terms
Attorney-Client Privilege in IR
The legal protection that can keep certain incident-response work confidential when it is done under the direction of legal counsel. It shapes how investigations are structured, communicated, and documented during major incidents.
Attribute-Based Access Control
An access model that uses attributes such as role, location, device, or sensitivity to make decisions.
Attributes
In identity and access management, the pieces of information describing a user or entity, such as department, role, location, or clearance. Attributes drive modern authorization decisions and must be kept accurate to be trusted.
Attribution
The effort to determine who is behind an attack, such as a specific group or nation-state, based on tools, infrastructure, and behavior. It is useful for context but notoriously uncertain and easy to spoof.
Audience Analysis
Considering who will read and must follow a security policy, so the wording, detail, and tone fit them. A policy written for engineers differs from one for all staff, and matching the audience is what makes it usable.
Audit Automation
Using tools and scripts to perform audit work that was traditionally manual, such as pulling evidence, testing controls across all records instead of a sample, and tracking findings. It lets auditors cover more ground with less repetitive effort.
Audit Career Paths
The routes a professional can take within auditing, from staff auditor through senior, manager, and leadership roles, or into specializations like IT or cybersecurity audit. It maps how experience and certifications open new roles.
Audit Career Transitions
The shifts auditors make between roles, specialties, or industries, such as moving from external to internal audit, into IT or security audit, or out of audit into risk or compliance. Each transition draws on transferable audit skills.
Audit Categories
The major kinds of audit, such as financial, operational, compliance, and IT or cybersecurity audits, each with a different objective and scope. Knowing the category sets expectations for what an audit will and will not cover.
Audit Certifications
Professional credentials that validate audit expertise, such as CISA for IT audit, CIA for internal audit, or CPA for financial audit. They signal competence to employers and are often required for advancement.
Audit Coordination
From a GRC perspective, managing the logistics and relationships of an audit on the organization's side: scheduling, gathering evidence, routing auditor requests to the right owners, and keeping the engagement running smoothly.
Audit Cycle
The end-to-end sequence of an audit: preparation, fieldwork or execution, findings, reporting, and follow-up. Understanding the cycle helps an organization know what each phase requires and prepare for it.
Audit Discipline
The body of professional rigor that defines good auditing: systematic methodology, evidence-based conclusions, objectivity, and adherence to standards. It is what makes audit results credible and repeatable.
Audit Engagement Management
Running an external audit engagement well from the company's side: selecting the firm, scoping the work, coordinating evidence and timelines, and managing distribution of the resulting report, so the audit is efficient and the outcome is usable.
Audit Ethics
The ethical obligations that govern auditors, including objectivity, integrity, confidentiality, and avoiding conflicts of interest. Because others rely on audit conclusions, ethical lapses undermine the entire value of the work.
Audit Execution
The fieldwork phase of an audit, where the auditor tests controls, examines evidence, conducts interviews, and gathers the support for conclusions. It is where the audit's actual testing happens.
Audit Findings
The issues an audit identifies, such as a control that is missing, not operating, or operating ineffectively, each documented with evidence and usually a recommendation. Findings are the main output an organization must act on.
Audit Firm Selection
Audit firm selection is the process of choosing an independent assessment partner based on scope, expertise, independence, and the compliance framework being assessed.
Audit Independence
The auditor's freedom from influence or conflicts that could bias their conclusions, in both fact and appearance. Without independence, an audit's assurance is worthless because its objectivity cannot be trusted.
Audit Innovation
Improving how audits are done through new techniques and technology, such as data analytics, continuous auditing, and automation, to increase coverage, speed, and insight beyond traditional sample-based methods.
Audit Integration
Connecting audit with the rest of the organization's governance, risk, and assurance activities so efforts are coordinated rather than siloed, reducing duplicate testing and giving a unified view of control health.
Audit Leadership Path
The progression toward leading an audit function, advancing from auditor to manager, director, and ultimately chief audit executive. It adds skills in strategy, stakeholder management, and running an audit program.
Audit Lessons Learned
Reflecting after an audit on what went well and what could improve, both in the audit process and in the organization's response, so future audits run more smoothly and recurring issues get addressed.
Audit Log Analysis
Examining cloud and system audit logs, the records of who did what and when, to detect suspicious activity, investigate incidents, and verify that controls are working. In cloud security it is a primary source of detection and forensic evidence.
Audit Maturity Indicators
Signs that an audit function has moved beyond basic compliance checking toward a strategic, well-run capability, such as risk-based planning, data analytics, integration with other functions, and demonstrable business value.
Audit Preparation
The work an organization does before an audit begins: confirming scope, gathering and organizing evidence, briefing control owners, and resolving known gaps, so the audit runs efficiently and surfaces fewer surprises.
Audit Profession
The field of auditing as a recognized professional discipline, with its own standards, ethics, certifications, and career structure. Membership implies adhering to shared expectations of competence and integrity.
Audit Program Management
Running the overall portfolio of audits over time: building a risk-based audit plan, allocating resources, scheduling engagements, tracking findings to closure, and reporting on the function's performance.
Audit Quality
How well an audit achieves its purpose: conclusions that are accurate, well-evidenced, and relevant, reached through sound methodology and objectivity. Poor quality erodes the trust that makes audit useful.
Audit Report Distribution
Controlling who receives an audit report and how, since reports often contain sensitive findings and may be shared with customers, regulators, or partners under specific conditions. Distribution must balance transparency with confidentiality.
Audit Skills Development
Building the competencies an auditor needs over a career, spanning technical knowledge, methodology, data analysis, communication, and judgment. It is how auditors stay effective and qualify for advancement.
Audit Specializations
Focused areas an auditor can develop expertise in, such as IT audit, cybersecurity audit, financial audit, or specific industries. Specializing lets an auditor handle complex, domain-specific risks that generalists cannot.