Chapter 20

Independent Assessor Audit Guide

Abstract

Independent assessors review the Security Package and test the security controls for compliance. Tests for confidentiality, integrity, and availability are performed. Tests can be manual or automated, or a combination of both. Independent assessors commonly use checklists for performing security reviews and audits. Audits are also performed by Inspector Generals and the Government Accountability Office.

Keywords

Independent assessor; Integrity; Confidentiality; Availability; Audit; Scanners; Security testing tools; Tools; GAO; Government Accountability Office

To give no trust is to get no trust.

—Lao-Tzu (sixth century B.C.)

Topics in this chapter

• Testing against the system’s security control baseline ...

Get FISMA Compliance Handbook now with O’Reilly online learning.

O’Reilly members experience live online training, plus books, videos, and digital content from 200+ publishers.