A city CISO asks the internal security and audit teams to design ongoing tests of IAM and network controls that the organization itself will execute under city authority. What are they primarily building?
Select an answer to reveal the explanation.
Short Explanation
When your own audit and security folks plan the exams you will give yourselves—under the city's own roof and rules—that is an internal assessment strategy. Outside attestations and bug bounties are different animals.
Full Explanation
Internal assessment strategies define how in-house audit and security teams plan, schedule, and perform control tests and audits within organizational authority. They differ from external or independent third-party attestations and from unstructured testing without governance. Bug bounties may supplement but do not alone constitute a complete internal strategy.