Audit
What is Audit?
A systematic, independent examination of an organisation's activities, processes, or financial records to verify compliance with standards, regulations, or internal policies.
Related terms
Frameworks that govern audit
What the standards actually require on audit
Requirements naming audit across 6 standards, quoted from the control text.
Requirement defined in ISO 19011:2018, clause 6.6 (Completing audit). See licensed source for normative text. Implementation focus is to demonstrate conformity with the obligations of this clause through the artefacts listed in evidence_requirements.
iso-19011-2018::6.6 · Completing audit →Allocate audit log storage capacity to accommodate FedRAMP-defined retention period.
AU-4 · Audit Log Storage Capacity →Guidance on determining audit time based on effective number of personnel concept
27006-C · Audit time guidance →Plan ISMS audit, prepare documents and verify objectives, scope, criteria and risks.
27007-6.2 · Preparing Audit Activities →Allocate audit log storage capacity to accommodate FedRAMP-defined retention period.
AU-4 · Audit Log Storage Capacity →Cross-organizational Audit Logging. Employ [organization-defined] for coordinating [organization-defined] among external organizations when audit information is transmitted across organizational boundaries
NIST800-AU-16 · Cross-organizational Audit Logging. Employ [organization-defined] for coordinating [organization-defined] among external organizations when audit information is transmitted across organizational boundaries →Questions people ask about audit
What is Audit?
Why is Audit important for compliance?
What concepts are related to Audit?
Which compliance frameworks address Audit?
Where can I learn more about Audit?
See how Audit applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.