A city CISO contrasts an annual independent audit of payroll ITGCs with the SOC's weekly vulnerability scans. What distinction best explains their different purposes?
Select an answer to reveal the explanation.
Short Explanation
Audit is the formal report card for outsiders and leadership; weekly scans are the gym routine that keeps you sharp. One gives assurance on design and operation, the other feeds continuous fixing. They work together — they are not the same sport.
Full Explanation
Audits are assurance engagements that independently evaluate whether controls are suitably designed and operating, often for governance, regulators, or external stakeholders. Continuous security testing and monitoring activities such as vulnerability scanning support operational risk reduction but do not by themselves constitute independent audit assurance. CISSP practitioners must keep those purposes distinct when planning assessment strategies.