Chapter 20

Independent Assessor Audit Guide

Abstract

Independent assessors review the Security Package and test the security controls for compliance. Tests for confidentiality, integrity, and availability are performed. Tests can be manual or automated, or a combination of both. Independent assessors commonly use checklists for performing security reviews and audits. Audits are also performed by Inspector Generals and the Government Accountability Office.

Keywords

Independent assessor; Integrity; Confidentiality; Availability; Audit; Scanners; Security testing tools; Tools; GAO; Government Accountability Office

To give no trust is to get no trust.

—Lao-Tzu (sixth century B.C.)

Topics in this chapter

• Testing against the system’s security control baseline ...

Get FISMA Compliance Handbook now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.