Leadership hires an outside firm to review the city access-control policy implementation for gaps, without requesting a formal regulated attestation report. Which assessment type best fits?
Select an answer to reveal the explanation.
Short Explanation
Somebody from outside the org walks the policy and points at gaps—but you are not buying a stamped PCI attestation. That is external assessment: fresh eyes, not necessarily a formal third-party cert letter.
Full Explanation
External assessments use resources outside the organization's day-to-day control to evaluate controls or policy adherence, providing independence without necessarily constituting a regulated third-party attestation (such as a PCI QSA engagement). Internal-only monitoring and tabletop-only activities do not match this outside-review pattern. Not every external reviewer produces a formal attestation artifact.